CVE-2020-14350

EUVD-2020-6494
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
9.5 ≤
𝑥
< 9.5.23
postgresqlpostgresql
9.6 ≤
𝑥
< 9.6.19
postgresqlpostgresql
10.0 ≤
𝑥
< 10.14
postgresqlpostgresql
11.0 ≤
𝑥
< 11.9
postgresqlpostgresql
12.0 ≤
𝑥
< 12.4
debiandebian_linux
9.0
opensuseleap
15.1
opensuseleap
15.2
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
20.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
bionic
Fixed 10.14-0ubuntu0.18.04.1
released
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-12
bionic
dne
focal
Fixed 12.4-0ubuntu0.20.04.1
released
groovy
Fixed 12.4-1
released
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-9.1
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-9.3
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
deferred
xenial
dne
postgresql-9.5
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
Fixed 9.5.23-0ubuntu0.16.04.1
released