cbcvebase.
CVE-2018-1058
published 2018-03-02

CVE-2018-1058: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to…

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
14.14%
96.2th percentile
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
msrccm1_postgresql_12.7-1_on_cbl_mariner_1.0
opensuseleap
opensuseleap
postgresqlpostgresql
postgresqlpostgresql>= 0 < 11.9-r011.9-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 12.4-r012.4-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 12.4-r012.4-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 12.4-r012.4-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 12.4-r012.4-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 9.5.12-r09.5.12-r0
postgresqlpostgresql>= 0 < 9.6.8-r09.6.8-r0
postgresqlpostgresql>= 0 < 9.6.8-r09.6.8-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 0 < 11.9-r011.9-r0
postgresqlpostgresql>= 0 < 10.3-r010.3-r0
postgresqlpostgresql>= 10.0 < 10.310.3

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker creates objects in the 'public' schema to execute arbitrary SQL functions under the identity running replication (often a superuser), exploiting uncontrolled search_path in logical replication
  • CVE-2018-1058 attack vector: a user modifies the search_path to alter query behavior for other users, including superusers — monitor for unexpected schema object creation in 'public' by non-privileged users
  • Installations that have adopted a documented 'secure schema usage pattern' are not vulnerable — absence of this pattern is a risk indicator
  • pg_dump and other PostgreSQL client applications are affected attack surfaces due to uncontrolled search_path element
  • ·Affected PostgreSQL versions are 9.3 through 10; PostgreSQL 11+ (with proper patching) and Red Hat Enterprise Linux 8 packages are not affected
  • ·The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path, but logical replication continued to leave search_path unchanged (tracked separately as CVE-2020-14349)
  • ·Upstream mitigation guidance (short of patching) is available at the PostgreSQL wiki guide for CVE-2018-1058 covering search_path hardening

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.