CVE-2024-10979

CVSS V2 None CVSS V3 None
Description
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Overview
  • CVE ID
  • CVE-2024-10979
  • Assigner
  • PostgreSQL
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-14T13:00:08.586Z
  • Last Modified Date
  • 2024-11-14T14:36:38.312Z
References
History
Created Old Value New Value Data Type Notes
2024-11-15 13:18:30 Added to TrackCVE