Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-2454
HistoryMay 12, 2023 - 12:00 a.m.

CVE-2023-2454

2023-05-1200:00:00
ubuntu.com
ubuntu.com
9
postgresql
cve-2023-2454
code execution
database privileges
schema element

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.9%

schema_element defeats protective search_path changes; It was found that
certain database calls in PostgreSQL could permit an authed attacker with
elevated database-level privileges to execute arbitrary code.

Notes

Author Note
leosilva PostgreSQL 9.3 is end of life upstream, and no updates are are available. Marking as deferred in -esm-main releases. PostgreSQL 9.3 is end of life upstream, and no updates are are available. Marking as deferred in -esm-main releases.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpostgresql-10< 10.23-0ubuntu0.18.04.2UNKNOWN
ubuntu20.04noarchpostgresql-12< 12.15-0ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchpostgresql-14< 14.8-0ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchpostgresql-14< 14.8-0ubuntu0.22.10.1UNKNOWN
ubuntu23.04noarchpostgresql-15< 15.3-0ubuntu0.23.04.1UNKNOWN
ubuntu14.04noarchpostgresql-9.3< anyUNKNOWN
ubuntu16.04noarchpostgresql-9.5< 9.5.25-0ubuntu0.16.04.1+esm4UNKNOWN

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.9%