CVE-2023-39417 Information

Description

IN THE EXTENSION SCRIPT a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@ @extschema@ or @extschema:…@ inside a quoting construct (dollar quoting ’’ or ). If an administrator has installed files of a vulnerable trusted non-bundled extension an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

Reference

https://www.postgresql.org/support/security/CVE-2023-39417 https://access.redhat.com/security/cve/CVE-2023-39417 https://bugzilla.redhat.com/show_bug.cgi?id=2228111

Share on: