CVE-2022-1552

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2022
Last modified:
07/11/2023

Description

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 10.0 (including) 10.21 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 11.0 (including) 11.16 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 12.0 (including) 12.11 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 13.0 (including) 13.7 (excluding)
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* 14.0 (including) 14.3 (excluding)