HIGH 8.0 Microsoft
CVE-2022-2625
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema the ability to lure or wait for an administrator to create or update an affected extension in that schema and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites this flaw allows an attacker to run arbitrary code as the victim role which may be a superuser.
Microsoft Security Update 2022-Aug: A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema the ability to lure or wait for an administrator to create or update an affected extension in that schema and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites this flaw allows an attacker to run arbitrary code as the victim role which may be a superuser.
Affected Products
- cm1 postgresql 12.12-1 on CBL Mariner 1.0
- cbl2 postgresql 14.5-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-2625
- https://nvd.nist.gov/vuln/detail/CVE-2022-2625
This high severity vulnerability with a CVSS score of 8.0 was published on 2022-08-09 via Microsoft. Affected: cm1 postgresql 12.12-1 on CBL Mariner 1.0, cbl2 postgresql 14.5-1 on CBL Mariner 2.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.