← Back

CVE-2017-16082

nvd nist
Published: Jun 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

Affected (6)

Products: Node Postgres: Pg
1 product
Pg
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Node Postgres
After 5.0.0 to 5.2.1
From 2.0.0 to 2.11.2
From 3.0.0 to 3.6.4
From 4.0.0 to 4.5.7
From 6.0.0 to 6.4.2
From 7.0.0 to 7.1.2

References (4)

Source: support@hackerone.com
ExploitThird Party Advisory
Source: support@hackerone.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.