CVE Vulnerabilities

CVE-2024-1713

Unexpected Status Code or Return Value

Published: Mar 14, 2024 | Modified: Jan 23, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.

Weakness

The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.

Affected Software

Name Vendor Start Version End Version
Plv8 Plv8 3.2.1 (including) 3.2.1 (including)

References