Lucene search

K
osvGoogleOSV:USN-5440-1
HistoryMay 24, 2022 - 11:46 a.m.

postgresql-10, postgresql-12, postgresql-13, postgresql-14 vulnerability

2022-05-2411:46:11
Google
osv.dev
4

7.9 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.7%

Alexander Lakhin discovered that PostgreSQL incorrectly handled the
security restricted operation sandbox when a privileged user is maintaining
another user’s objects. An attacker having permission to create non-temp
objects can use this issue to execute arbitrary commands as the superuser.