CVE-2023-23554

CVSS V2 None CVSS V3 None
Description
Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm executes functions without specifying schema names. Under certain conditions, pg_ivm may be tricked to execute unexpected functions from other schemas with the IMMV owner's privilege. If this vulnerability is exploited, an unexpected function provided by an attacker may be executed with the privilege of the materialized view owner.
Overview
  • CVE ID
  • CVE-2023-23554
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-07T01:15:10
  • Last Modified Date
  • 2023-03-14T15:54:54
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:sraoss:pg_ivm:*:*:*:*:*:postgresql:*:* 1 OR 1.5.1
References
History
Created Old Value New Value Data Type Notes
2023-04-17 06:01:22 Added to TrackCVE
2023-04-17 06:01:25 Weakness Enumeration new