← Back

CVE-2022-2625

nvd nist
Published: Aug 18, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD

Description

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

Affected (12)

1 product
Postgresql
1 product
Fedora
1 product
Enterprise Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 10.0 to 10.22
From 11.0 to 11.17
From 12.0 to 12.12
From 13.0 to 13.8
From 14.0 to 14.5
Version 15 beta1
Version 15 beta2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 36
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Version 8.0
Version 9.0

References (6)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.