PostgreSQL psql Interactive Terminal Vulnerability in Multiple Versions
CVE-2020-25696
7.5HIGH
Summary
A vulnerability in the psql interactive terminal of PostgreSQL prior to specified versions allows an attacker exploiting a compromised server to run arbitrary code under the operating system account that executes psql. This can severely compromise data confidentiality and integrity, as well as system availability. Users of affected versions should apply security updates promptly to mitigate the risk associated with this vulnerability.
Affected Version(s)
PostgreSQL All PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved