CVE-2024-10979
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/11/2024
Last modified:
11/02/2025
Description
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 12.0 (including) | 12.21 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 13.0 (including) | 13.17 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 14.0 (including) | 14.14 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 15.0 (including) | 15.9 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 16.0 (including) | 16.5 (excluding) |
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | 17.0 (including) | 17.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page