CVE-2018-1058
published 2018-03-02CVE-2018-1058: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
14.14%
96.2th percentile
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| msrc | cm1_postgresql_12.7-1_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | >= 0 < 11.9-r0 | 11.9-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 9.5.12-r0 | 9.5.12-r0 |
| postgresql | postgresql | >= 0 < 9.6.8-r0 | 9.6.8-r0 |
| postgresql | postgresql | >= 0 < 9.6.8-r0 | 9.6.8-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 0 < 11.9-r0 | 11.9-r0 |
| postgresql | postgresql | >= 0 < 10.3-r0 | 10.3-r0 |
| postgresql | postgresql | >= 10.0 < 10.3 | 10.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacker creates objects in the 'public' schema to execute arbitrary SQL functions under the identity running replication (often a superuser), exploiting uncontrolled search_path in logical replication ↗
- →CVE-2018-1058 attack vector: a user modifies the search_path to alter query behavior for other users, including superusers — monitor for unexpected schema object creation in 'public' by non-privileged users ↗
- →Installations that have adopted a documented 'secure schema usage pattern' are not vulnerable — absence of this pattern is a risk indicator ↗
- →pg_dump and other PostgreSQL client applications are affected attack surfaces due to uncontrolled search_path element ↗
- ·Affected PostgreSQL versions are 9.3 through 10; PostgreSQL 11+ (with proper patching) and Red Hat Enterprise Linux 8 packages are not affected ↗
- ·The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path, but logical replication continued to leave search_path unchanged (tracked separately as CVE-2020-14349) ↗
- ·Upstream mitigation guidance (short of patching) is available at the PostgreSQL wiki guide for CVE-2018-1058 covering search_path hardening ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: Uncontrolled search path element in logical replication
vendor_redhat·2020-08-13·CVSS 8.8
CVE-2020-14349 [HIGH] CWE-20 postgresql: Uncontrolled search path element in logical replication
postgresql: Uncontrolled search path element in logical replication
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
A flaw was found in PostgreSQL, where it did not properly sanitize the search_path during logical replication. This flaw allows an authenticated attacker to use this flaw in an attack similar to CVE-2018-1058 to execute an arbitrary SQL command in the user's context for replication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Statement:
Microsoft
It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an
vendor_msrc·2020-08-11·CVSS 7.1
CVE-2020-14349 [HIGH] CWE-89 It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an
It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058 in order to execute arbitrary SQL command in the context of the user used for replication.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX i
Ubuntu
PostgreSQL vulnerability
vendor_ubuntu·2018-03-06
CVE-2018-1058 PostgreSQL vulnerability
Title: PostgreSQL vulnerability
Summary: PostgreSQL could be made to execute arbitrary code.
It was discovered that PostgreSQL incorrectly handled certain settings.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: Uncontrolled search path element in pg_dump and other client applications
vendor_redhat·2018-03-01·CVSS 8.8
CVE-2018-1058 [HIGH] CWE-20 postgresql: Uncontrolled search path element in pg_dump and other client applications
postgresql: Uncontrolled search path element in pg_dump and other client applications
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database.
Statement: This issue affects the versions of Postgresql as shipped with Red Hat Satellite 5. Red Hat Product Security has rated this issue as having security impact of Low. A future update may address this issue. For additio
GHSA
GHSA-2783-h34h-q54q: It was found that PostgreSQL versions before 12
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-14349 [HIGH] CWE-89 GHSA-2783-h34h-q54q: It was found that PostgreSQL versions before 12
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
GHSA
GHSA-wj3f-f94q-2r98: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users
ghsa_unreviewed·2022-05-13
CVE-2018-1058 [HIGH] GHSA-wj3f-f94q-2r98: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
OSV
CVE-2020-14349: It was found that PostgreSQL versions before 12
osv·2020-08-24·CVSS 8.8
CVE-2020-14349 [HIGH] CVE-2020-14349: It was found that PostgreSQL versions before 12
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
OSV
CVE-2018-1058: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users
osv·2018-03-02·CVSS 8.8
CVE-2018-1058 [HIGH] CVE-2018-1058: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
bugzilla·2020-08-04·CVSS 8.8
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path, but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the "public" schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented "secure schema usage pattern" are not vulnerable.
Discussion:
Created postgresql tracking bugs for this issue:
Affects: fedora-all [bug 1868662]
Created postgresql:10/postgresql tracking bugs f
Bugzilla
CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
bugzilla·2018-03-02·CVSS 8.8
CVE-2018-1058 [HIGH] CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
bugzilla·2018-03-02·CVSS 8.8
CVE-2018-1058 [HIGH] CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [epel-7]
bugzilla·2018-03-02·CVSS 8.8
CVE-2018-1058 [HIGH] CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [epel-7]
CVE-2018-1058 mingw-postgresql: postgresql: Uncontrolled search path element in pg_dump and other client applications [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discus
Bugzilla
CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications
bugzilla·2018-02-20·CVSS 8.8
CVE-2018-1058 [HIGH] CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications
CVE-2018-1058 postgresql: Uncontrolled search path element in pg_dump and other client applications
From upstream advisory:
Supported, Vulnerable Versions: 9.3 - 10. The security team typically does
not test unsupported versions, but this problem is quite old.
The PostgreSQL search_path setting determines schemas searched for tables,
functions, operators, etc. The pg_dump client application chooses search_path
settings such that every schema may appear at the front of its search path.
This permits a user with CREATE privilege on any schema to execute arbitrary
SQL functions under the identity of the user running pg_dump, often a
superuser. This is exploitable in the default configuration, where all users
have CREATE privilege on schema "public". The pg_upgrade implementation
invokes pg_
http://www.securityfocus.com/bid/103221https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=1547044https://usn.ubuntu.com/3589-1/https://www.postgresql.org/about/news/1834/http://www.securityfocus.com/bid/103221https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=1547044https://usn.ubuntu.com/3589-1/https://www.postgresql.org/about/news/1834/
2018-03-02
Published