CVE-2022-2625

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:15:beta1:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:15:beta2:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:01

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2113825 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2113825 - Issue Tracking, Third Party Advisory
References () https://security.gentoo.org/glsa/202211-04 - Third Party Advisory () https://security.gentoo.org/glsa/202211-04 - Third Party Advisory
References () https://www.postgresql.org/about/news/postgresql-145-138-1212-1117-1022-and-15-beta-3-released-2496/ - Release Notes, Vendor Advisory () https://www.postgresql.org/about/news/postgresql-145-138-1212-1117-1022-and-15-beta-3-released-2496/ - Release Notes, Vendor Advisory

Information

Published : 2022-08-18 19:15

Updated : 2024-11-21 07:01


NVD link : CVE-2022-2625

Mitre link : CVE-2022-2625

CVE.ORG link : CVE-2022-2625


JSON object : View

Products Affected

fedoraproject

  • fedora

redhat

  • enterprise_linux

postgresql

  • postgresql
CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')