cbcvebase.
CVE-2023-2454
published 2023-06-09

CVE-2023-2454: schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-13 13.11-0+deb11u1 (bullseye)postgresql-13 13.11-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.11-0+deb11u1 (bullseye)postgresql-13 13.11-0+deb11u1 (bullseye)
fedoraprojectfedora
postgresqlpostgresql
postgresqlpostgresql>= 11.0 < 11.2011.20
postgresqlpostgresql>= 12.0 < 12.1512.15
postgresqlpostgresql>= 13.0 < 13.1113.11
postgresqlpostgresql>= 14.0 < 14.814.8
postgresqlpostgresql>= 15.0 < 15.315.3
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH