CVE-2023-39417

CVSS V2 None CVSS V3 None
Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Overview
  • CVE ID
  • CVE-2023-39417
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-08-11T13:15:09
  • Last Modified Date
  • 2023-08-18T17:58:49
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 11.0 11.21
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 12.0 12.16
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 13.0 13.12
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 14.0 14.9
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 1 OR 15.0 15.4
cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* 1 OR
References
History
Created Old Value New Value Data Type Notes
2023-09-06 03:37:14 Added to TrackCVE
2023-09-06 03:37:17 Weakness Enumeration new