← Back

CVE-2024-10979

nvd nist
Published: Nov 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Affected (6)

1 product
Postgresql
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Postgresql
From 12.0 to 12.21
From 13.0 to 13.17
From 14.0 to 14.14
From 15.0 to 15.9
From 16.0 to 16.5
From 17.0 to 17.1

References (4)

Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.