Lucene search

K
redhatcveRedhat.comRH:CVE-2018-16850
HistoryApr 04, 2020 - 5:44 a.m.

CVE-2018-16850

2020-04-0405:44:50
redhat.com
access.redhat.com
14

EPSS

0.004

Percentile

74.0%

A SQL Injection flaw has been discovered in PostgreSQL server in the way triggers that enable transition relations are dumped. The transition relation name is not correctly quoted and it may allow an attacker with CREATE privilege on some non-temporary schema or TRIGGER privilege on some table to create a malicious trigger that, when dumped and restored, would result in additional SQL statements being executed.