CVE Vulnerabilities

CVE-2023-2454

Published: Jun 09, 2023 | Modified: Jul 06, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 11.0 (including) 11.20 (excluding)
Postgresql Postgresql 12.0 (including) 12.15 (excluding)
Postgresql Postgresql 13.0 (including) 13.11 (excluding)
Postgresql Postgresql 14.0 (including) 14.8 (excluding)
Postgresql Postgresql 15.0 (including) 15.3 (excluding)

References