CVE-2021-3515

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/06/2021
Last modified:
07/10/2022

Description

A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription().

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:2ndquadrant:pglogical:*:*:*:*:*:*:*:* 2.3.4 (excluding)
cpe:2.3:a:2ndquadrant:pglogical:*:*:*:*:*:*:*:* 3.0.0 (including) 3.6.26 (excluding)


References to Advisories, Solutions, and Tools