PostgreSQL Search Path Misconfiguration Vulnerability in Extensions
CVE-2020-14350
What is CVE-2020-14350?
Certain PostgreSQL extensions contain a misconfiguration within their installation scripts that fails to use the search_path securely. This flaw permits an attacker with sufficient privileges to manipulate an administrator into inadvertently executing a crafted script during the installation or update process. The affected versions span PostgreSQL 12.4, 11.9, 10.14, 9.6.19, and 9.5.23 and require immediate attention to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PostgreSQL PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved