CVE-2019-10211

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
𝑥
< 9.4.24
postgresqlpostgresql
9.5.0 ≤
𝑥
< 9.5.19
postgresqlpostgresql
9.6.0 ≤
𝑥
< 9.6.15
postgresqlpostgresql
10.0 ≤
𝑥
< 10.10
postgresqlpostgresql
11.0 ≤
𝑥
< 11.5
𝑥
= Vulnerable software versions