cbcvebase.
CVE-2023-39417
published 2023-08-11

CVE-2023-39417: IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianpostgresql-13< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.13-0+deb11u1 (bullseye)postgresql-13 13.13-0+deb11u1 (bullseye)
msrccbl2_postgresql_14.10-1_on_cbl_mariner_2.0
postgresqlpostgresql>= 11.0 < 11.2111.21
postgresqlpostgresql>= 12.0 < 12.1612.16
postgresqlpostgresql>= 13.0 < 13.1213.12
postgresqlpostgresql>= 14.0 < 14.914.9
postgresqlpostgresql>= 15.0 < 15.415.4
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH