CVE-2020-14349
published 2020-08-24CVE-2020-14349: It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An…
PriorityP341high7.1CVSS 3.1
AVNACHPRLUIRSUCHIHAH
EPSS
2.23%
80.8th percentile
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | cm1_postgresql_12.7-1_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| postgresql | postgresql | >= 0 < 11.9-r0 | 11.9-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 12.4-r0 | 12.4-r0 |
| postgresql | postgresql | >= 0 < 11.9-r0 | 11.9-r0 |
| postgresql | postgresql | >= 10.0 < 10.14 | 10.14 |
| postgresql | postgresql | >= 11.0 < 11.9 | 11.9 |
| postgresql | postgresql | >= 12.0 < 12.4 | 12.4 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_msrc7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2020-08-25·CVSS 7.1
CVE-2020-14349 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Noah Misch discovered that PostgreSQL incorrectly handled the search_path
setting when used with logical replication. A remote attacker could
possibly use this issue to execute arbitrary SQL code. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14349)
Andres Freund discovered that PostgreSQL incorrectly handled search path
elements in CREATE EXTENSION. A remote attacker could possibly use this
issue to execute arbitrary SQL code. (CVE-2020-14350)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: Uncontrolled search path element in logical replication
vendor_redhat·2020-08-13·CVSS 8.8
CVE-2020-14349 [HIGH] CWE-20 postgresql: Uncontrolled search path element in logical replication
postgresql: Uncontrolled search path element in logical replication
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
A flaw was found in PostgreSQL, where it did not properly sanitize the search_path during logical replication. This flaw allows an authenticated attacker to use this flaw in an attack similar to CVE-2018-1058 to execute an arbitrary SQL command in the user's context for replication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Statement:
Microsoft
It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an
vendor_msrc·2020-08-11·CVSS 7.1
CVE-2020-14349 [HIGH] CWE-89 It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an
It was found that PostgreSQL versions before 12.4 before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058 in order to execute arbitrary SQL command in the context of the user used for replication.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX i
GHSA
GHSA-2783-h34h-q54q: It was found that PostgreSQL versions before 12
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-14349 [HIGH] CWE-89 GHSA-2783-h34h-q54q: It was found that PostgreSQL versions before 12
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
OSV
postgresql-10, postgresql-12, postgresql-9.5 vulnerabilities
osv·2020-08-25·CVSS 7.1
CVE-2020-14349 [HIGH] postgresql-10, postgresql-12, postgresql-9.5 vulnerabilities
postgresql-10, postgresql-12, postgresql-9.5 vulnerabilities
Noah Misch discovered that PostgreSQL incorrectly handled the search_path
setting when used with logical replication. A remote attacker could
possibly use this issue to execute arbitrary SQL code. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14349)
Andres Freund discovered that PostgreSQL incorrectly handled search path
elements in CREATE EXTENSION. A remote attacker could possibly use this
issue to execute arbitrary SQL code. (CVE-2020-14350)
OSV
CVE-2020-14349: It was found that PostgreSQL versions before 12
osv·2020-08-24·CVSS 8.8
CVE-2020-14349 [HIGH] CVE-2020-14349: It was found that PostgreSQL versions before 12
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication [fedora-all]
bugzilla·2020-08-13·CVSS 7.1
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication [fedora-all]
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2020-14349 postgresql:12/postgresql: Uncontrolled search path element in logical replication [fedora-all]
bugzilla·2020-08-13·CVSS 7.1
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql:12/postgresql: Uncontrolled search path element in logical replication [fedora-all]
CVE-2020-14349 postgresql:12/postgresql: Uncontrolled search path element in logical replication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2020-14349 postgresql:11/postgresql: Uncontrolled search path element in logical replication [fedora-all]
bugzilla·2020-08-13·CVSS 7.1
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql:11/postgresql: Uncontrolled search path element in logical replication [fedora-all]
CVE-2020-14349 postgresql:11/postgresql: Uncontrolled search path element in logical replication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2020-14349 postgresql:10/postgresql: Uncontrolled search path element in logical replication [fedora-all]
bugzilla·2020-08-13·CVSS 7.1
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql:10/postgresql: Uncontrolled search path element in logical replication [fedora-all]
CVE-2020-14349 postgresql:10/postgresql: Uncontrolled search path element in logical replication [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
bugzilla·2020-08-04·CVSS 8.8
CVE-2020-14349 [HIGH] CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication
The PostgreSQL search_path setting determines schemas searched for tables, functions, operators, etc. The CVE-2018-1058 fix caused most PostgreSQL-provided client applications to sanitize search_path, but logical replication continued to leave search_path unchanged. Users of a replication publisher or subscriber database can create objects in the "public" schema and harness them to execute arbitrary SQL functions under the identity running replication, often a superuser. Installations having adopted a documented "secure schema usage pattern" are not vulnerable.
Discussion:
Created postgresql tracking bugs for this issue:
Affects: fedora-all [bug 1868662]
Created postgresql:10/postgresql tracking bugs f
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1865744https://security.gentoo.org/glsa/202008-13https://security.netapp.com/advisory/ntap-20200918-0002/https://usn.ubuntu.com/4472-1/http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1865744https://security.gentoo.org/glsa/202008-13https://security.netapp.com/advisory/ntap-20200918-0002/https://usn.ubuntu.com/4472-1/
2020-08-24
Published