CVE-2022-2625

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
postgresqlpostgresql
10.0 ≤
𝑥
< 10.22
postgresqlpostgresql
11.0 ≤
𝑥
< 11.17
postgresqlpostgresql
12.0 ≤
𝑥
< 12.12
postgresqlpostgresql
13.0 ≤
𝑥
< 13.8
postgresqlpostgresql
14.0 ≤
𝑥
< 14.5
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye (security)
13.16-0+deb11u1
fixed
bullseye
13.16-0+deb11u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
Fixed 10.22-0ubuntu0.18.04.1
released
xenial
dne
trusty
dne
postgresql-12
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
Fixed 12.12-0ubuntu0.20.04.1
released
bionic
dne
xenial
dne
trusty
dne
postgresql-13
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
postgresql-14
noble
dne
mantic
dne
lunar
dne
kinetic
not-affected
jammy
Fixed 14.5-0ubuntu0.22.04.1
released
focal
dne
bionic
dne
xenial
dne
trusty
dne
postgresql-9.1
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
postgresql-9.3
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
deferred
postgresql-9.5
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
ignored
trusty
dne