CVE-2022-2625

EUVD-2022-34872
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
10.0 ≤
𝑥
< 10.22
postgresqlpostgresql
11.0 ≤
𝑥
< 11.17
postgresqlpostgresql
12.0 ≤
𝑥
< 12.12
postgresqlpostgresql
13.0 ≤
𝑥
< 13.8
postgresqlpostgresql
14.0 ≤
𝑥
< 14.5
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
13.16-0+deb11u1
fixed
bullseye (security)
13.16-0+deb11u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-10
bionic
Fixed 10.22-0ubuntu0.18.04.1
released
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-12
bionic
dne
focal
Fixed 12.12-0ubuntu0.20.04.1
released
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-13
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-14
bionic
dne
focal
dne
jammy
Fixed 14.5-0ubuntu0.22.04.1
released
kinetic
not-affected
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-9.1
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
postgresql-9.3
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
deferred
xenial
dne
postgresql-9.5
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
ignored