Database/Control plane, storage & DevOps
PostgreSQL: TOCTOU race in pg_dump
CVSS 8.8CVE-2024-7348Control plane, storage & DevOpscurated
Impact
TOCTOU race in pg_dump -> an object creator runs arbitrary SQL as the (often superuser) dump operator
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; stop running scheduled pg_dump as superuser
References
Related entries
- PostgreSQL: With cert/trust+clientcert auth, a MITM can inject arbitrary SQL at connection setupCVE-2021-23214 · PostgreSQLHigh
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateCVE-2022-1552 · PostgreSQLHigh
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)CVE-2024-10979 · PostgreSQLHigh
- Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone Controller: Malformed BACnetCVE-2025-0657 · Automated Logic / Carrier i-Vu Gen5 BACnet router (drv_gen5_106-01-2380) and i-Vu Zone ControllerHigh
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerCVE-2025-23121 · Veeam Backup & ReplicationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.