Query Behavior Modification Flaw in PostgreSQL by PostgreSQL Global Development Group
CVE-2018-1058
Key Information:
- Status
- Vendor
- CVE Published:
- 2 March 2018
Badges
What is CVE-2018-1058?
A vulnerability exists in PostgreSQL that enables a user to manipulate the behavior of database queries for others. An attacker with a valid user account can exploit this flaw to execute code with superuser privileges, potentially compromising the integrity and security of the database system. The affected versions include 9.3 through 10, making it crucial for users to apply the necessary security updates to mitigate risks.
Affected Version(s)
postgresql 9.3 - 10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
