Database/Control plane, storage & DevOps
PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too late
CVSS 8.8CVE-2022-1552Control plane, storage & DevOpscurated
Impact
Autovacuum, REINDEX, CLUSTER etc. apply protections too late -> user code runs privileged
Who can reach it
Network (remote)
What to do
Control-plane: minor-version upgrade
References
Related entries
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)CVE-2024-10979 · PostgreSQLHigh
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupCVE-2021-23214 · PostgreSQLHigh
- Samba (AD DC): KDC and kpasswd share keysCVE-2022-2031 · Samba (AD DC)High
- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerCVE-2022-23182 · Intel Data Center ManagerHigh
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesCVE-2022-24842 · MinIOHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.