Database/Control plane, storage & DevOps
PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)
CVSS 8.8CVE-2024-10979Control plane, storage & DevOpscurated
Impact
PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH) -> arbitrary code execution
Who can reach it
Network (remote)
What to do
Control-plane: minor-version upgrade of the control-plane DB
References
Related entries
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupCVE-2021-23214 · PostgreSQLHigh
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateCVE-2022-1552 · PostgreSQLHigh
- Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attackerCVE-2024-20449 · Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP)High
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerCVE-2024-20536 · Cisco Nexus Dashboard Fabric Controller (SQL injection)High
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.