Search

Find a vulnerability

Search criteria

    68 vulnerabilities by PostgreSQL

    CERTFR-2026-AVI-0837

    Vulnerability from certfr_avis - Published: 2026-07-06 - Updated: 2026-07-06

    Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL JDBC PostgreSQL JDBC versions postérieures ou égales à 42.7.4 et antérieures à 42.7.12
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL JDBC versions post\u00e9rieures ou \u00e9gales \u00e0 42.7.4 et ant\u00e9rieures \u00e0 42.7.12",
          "product": {
            "name": "PostgreSQL JDBC",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-54291",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54291"
        }
      ],
      "initial_release_date": "2026-07-06T00:00:00",
      "last_revision_date": "2026-07-06T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0837",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-06T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL JDBC. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL JDBC",
      "vendor_advisories": [
        {
          "published_at": "2026-07-06",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-jdbc-42712-security-release-3340",
          "url": "https://www.postgresql.org/about/news/postgresql-jdbc-42712-security-release-3340/"
        }
      ]
    }

    CERTFR-2026-AVI-0718

    Vulnerability from certfr_avis - Published: 2026-06-10 - Updated: 2026-06-10

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une élévation de privilèges.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL Anonymizer versions antérieures à 3.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL Anonymizer versions ant\u00e9rieures \u00e0 3.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-9617",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9617"
        }
      ],
      "initial_release_date": "2026-06-10T00:00:00",
      "last_revision_date": "2026-06-10T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0718",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-06-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL. Elle permet \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2026-06-09",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-anonymizer-31-introducing-local-differential-privacy-3311",
          "url": "https://www.postgresql.org/about/news/postgresql-anonymizer-31-introducing-local-differential-privacy-3311/"
        }
      ]
    }

    CERTFR-2026-AVI-0559

    Vulnerability from certfr_avis - Published: 2026-05-12 - Updated: 2026-05-12

    De multiples vulnérabilités ont été découvertes dans PostgreSQL PgBouncer. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PgBouncer PgBouncer versions antérieures à 1.25.2
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PgBouncer versions ant\u00e9rieures \u00e0 1.25.2",
          "product": {
            "name": "PgBouncer",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-6665",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6665"
        },
        {
          "name": "CVE-2026-6667",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6667"
        },
        {
          "name": "CVE-2026-6664",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6664"
        },
        {
          "name": "CVE-2026-6666",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6666"
        }
      ],
      "initial_release_date": "2026-05-12T00:00:00",
      "last_revision_date": "2026-05-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0559",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-05-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL PgBouncer. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL PgBouncer ",
      "vendor_advisories": [
        {
          "published_at": "2026-05-11",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL pgbouncer-1252-released-3292",
          "url": "https://www.postgresql.org/about/news/pgbouncer-1252-released-3292/"
        }
      ]
    }

    CERTFR-2026-AVI-0216

    Vulnerability from certfr_avis - Published: 2026-02-26 - Updated: 2026-02-26

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL pgvector pgvector versions antérieures à 0.8.2
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "pgvector versions ant\u00e9rieures \u00e0 0.8.2",
          "product": {
            "name": "pgvector",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-3172",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-3172"
        }
      ],
      "initial_release_date": "2026-02-26T00:00:00",
      "last_revision_date": "2026-02-26T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0216",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-02-26T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2026-02-26",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL pgvector-082-released-3245",
          "url": "https://www.postgresql.org/about/news/pgvector-082-released-3245/"
        }
      ]
    }

    CERTFR-2026-AVI-0164

    Vulnerability from certfr_avis - Published: 2026-02-13 - Updated: 2026-02-13

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.12
    PostgreSQL PostgreSQL PostgreSQL versions 18.x antérieures à 18.2
    PostgreSQL PostgreSQL PostgreSQL versions antérieures à 14.21
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.8
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.16
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.12",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 18.x ant\u00e9rieures \u00e0 18.2",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions ant\u00e9rieures \u00e0 14.21",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.8",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.16",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-2006",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2006"
        },
        {
          "name": "CVE-2026-2005",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2005"
        },
        {
          "name": "CVE-2026-2003",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2003"
        },
        {
          "name": "CVE-2026-2007",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2007"
        },
        {
          "name": "CVE-2026-2004",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2004"
        }
      ],
      "initial_release_date": "2026-02-13T00:00:00",
      "last_revision_date": "2026-02-13T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0164",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-02-13T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2026-02-12",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-182-178-1612-1516-and-1421-released-3235",
          "url": "https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/"
        }
      ]
    }

    CERTFR-2025-AVI-1061

    Vulnerability from certfr_avis - Published: 2025-12-04 - Updated: 2025-12-04

    Une vulnérabilité a été découverte dans PostgreSQL PgBouncer. Elle permet à un attaquant de provoquer une injection SQL (SQLi).

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PgBouncer PgBouncer versions antérieures à 1.25.1

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PgBouncer versions ant\u00e9rieures \u00e0 1.25.1 ",
          "product": {
            "name": "PgBouncer",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-12819",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12819"
        }
      ],
      "initial_release_date": "2025-12-04T00:00:00",
      "last_revision_date": "2025-12-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1061",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-12-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Injection SQL (SQLi)"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL PgBouncer. Elle permet \u00e0 un attaquant de provoquer une injection SQL (SQLi).",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL PgBouncer",
      "vendor_advisories": [
        {
          "published_at": "2025-12-03",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL pgbouncer-1251-released-fixing-a-bunch-of-bugs-before-christmas-including-cve-2025-12819-3189",
          "url": "https://www.postgresql.org/about/news/pgbouncer-1251-released-fixing-a-bunch-of-bugs-before-christmas-including-cve-2025-12819-3189/"
        }
      ]
    }

    CERTFR-2025-AVI-1007

    Vulnerability from certfr_avis - Published: 2025-11-14 - Updated: 2025-11-14

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions antérieures à 13.23
    PostgreSQL PostgreSQL PostgreSQL versions 18.x antérieures à 18.1
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.15
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.20
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.11
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions ant\u00e9rieures \u00e0 13.23",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 18.x ant\u00e9rieures \u00e0 18.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.15",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.20",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.11",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-12818",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12818"
        },
        {
          "name": "CVE-2025-12817",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-12817"
        }
      ],
      "initial_release_date": "2025-11-14T00:00:00",
      "last_revision_date": "2025-11-14T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1007",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-11-14T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2025-11-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-181-177-1611-1515-1420-and-1323-released-3171",
          "url": "https://www.postgresql.org/about/news/postgresql-181-177-1611-1515-1420-and-1323-released-3171/"
        }
      ]
    }

    CERTFR-2025-AVI-0702

    Vulnerability from certfr_avis - Published: 2025-08-18 - Updated: 2025-08-18

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à la confidentialité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    L'éditeur annonce la fin de vie de PostgreSQL version 13.x. Cette version ne recevra plus de correctifs de sécurité à partir du 13 novembre 2025. L'éditeur recommande aux utilisateurs de migrer vers une version plus récente.

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.6
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.14
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.22
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.19
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.10
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.6",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.14",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.22",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.19",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.10",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "L\u0027\u00e9diteur annonce la fin de vie de PostgreSQL version 13.x. Cette version ne recevra plus de correctifs de s\u00e9curit\u00e9 \u00e0 partir du 13 novembre 2025. L\u0027\u00e9diteur recommande aux utilisateurs de migrer vers une version plus r\u00e9cente.",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-8715",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8715"
        },
        {
          "name": "CVE-2025-8713",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8713"
        },
        {
          "name": "CVE-2025-8714",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-8714"
        }
      ],
      "initial_release_date": "2025-08-18T00:00:00",
      "last_revision_date": "2025-08-18T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0702",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-08-18T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2025-08-14",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-176-1610-1514-1419-1322-and-18-beta-3-released-3118",
          "url": "https://www.postgresql.org/about/news/postgresql-176-1610-1514-1419-1322-and-18-beta-3-released-3118/"
        }
      ]
    }

    CERTFR-2025-AVI-0514

    Vulnerability from certfr_avis - Published: 2025-06-16 - Updated: 2025-06-16

    Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL JDBC PostgreSQL JDBC versions antérieures à 42.7.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL JDBC versions ant\u00e9rieures \u00e0 42.7.7",
          "product": {
            "name": "PostgreSQL JDBC",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-49146",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-49146"
        }
      ],
      "initial_release_date": "2025-06-16T00:00:00",
      "last_revision_date": "2025-06-16T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0514",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-06-16T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL JDBC. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL JDBC",
      "vendor_advisories": [
        {
          "published_at": "2025-06-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-jdbc-4277-security-update-for-cve-2025-49146-3088",
          "url": "https://www.postgresql.org/about/news/postgresql-jdbc-4277-security-update-for-cve-2025-49146-3088/"
        }
      ]
    }

    CERTFR-2025-AVI-0380

    Vulnerability from certfr_avis - Published: 2025-05-09 - Updated: 2025-05-09

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.18
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.13
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.21
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.9
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.5
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.18",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.13",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.21",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.9",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.5",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-4207",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-4207"
        }
      ],
      "initial_release_date": "2025-05-09T00:00:00",
      "last_revision_date": "2025-05-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0380",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-05-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2025-05-08",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-175-169-1513-1418-and-1321-released-3072",
          "url": "https://www.postgresql.org/about/news/postgresql-175-169-1513-1418-and-1321-released-3072/"
        }
      ]
    }

    CERTFR-2025-AVI-0339

    Vulnerability from certfr_avis - Published: 2025-04-22 - Updated: 2025-04-22

    Une vulnérabilité a été découverte dans PostgreSQL PgBouncer. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PgBouncer PgBouncer versions antérieures à 1.24.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PgBouncer versions ant\u00e9rieures \u00e0 1.24.1",
          "product": {
            "name": "PgBouncer",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-2291",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-2291"
        }
      ],
      "initial_release_date": "2025-04-22T00:00:00",
      "last_revision_date": "2025-04-22T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0339",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-04-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL PgBouncer. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL PgBouncer",
      "vendor_advisories": [
        {
          "published_at": "2025-04-21",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL pgbouncer-1241-released-fixes-cve-2025-2291-3059",
          "url": "https://www.postgresql.org/about/news/pgbouncer-1241-released-fixes-cve-2025-2291-3059/"
        }
      ]
    }

    CERTFR-2025-AVI-0130

    Vulnerability from certfr_avis - Published: 2025-02-14 - Updated: 2025-02-14

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.3
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.7
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.11
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.19
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.16
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.3",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.11",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.19",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.16",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-1094",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1094"
        }
      ],
      "initial_release_date": "2025-02-14T00:00:00",
      "last_revision_date": "2025-02-14T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0130",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-02-14T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2025-02-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-173-167-1511-1416-and-1319-released-3015",
          "url": "https://www.postgresql.org/about/news/postgresql-173-167-1511-1416-and-1319-released-3015/"
        }
      ]
    }

    CERTFR-2024-AVI-0987

    Vulnerability from certfr_avis - Published: 2024-11-15 - Updated: 2024-11-15

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.9
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.14
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.5
    PostgreSQL PostgreSQL PostgreSQL versions 17.x antérieures à 17.1
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.17
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.21
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.9",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.14",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.5",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 17.x ant\u00e9rieures \u00e0 17.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.17",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.21",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-10977",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10977"
        },
        {
          "name": "CVE-2024-10976",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10976"
        },
        {
          "name": "CVE-2024-10978",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10978"
        },
        {
          "name": "CVE-2024-10979",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10979"
        }
      ],
      "initial_release_date": "2024-11-15T00:00:00",
      "last_revision_date": "2024-11-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0987",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-11-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": "2024-11-14",
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL postgresql-171-165-159-1414-1317-and-1221-released-2955",
          "url": "https://www.postgresql.org/about/news/postgresql-171-165-159-1414-1317-and-1221-released-2955/"
        }
      ]
    }

    CERTFR-2024-AVI-0373

    Vulnerability from certfr_avis - Published: 2024-05-10 - Updated: 2024-05-10

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.15
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.12
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.19
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.3
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.15",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.12",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.19",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.3",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2024-4317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-4317"
        }
      ],
      "initial_release_date": "2024-05-10T00:00:00",
      "last_revision_date": "2024-05-10T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0373",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-05-10T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan\nclass=\"textit\"\u003ePostgreSQL\u003c/span\u003e. Elle permet \u00e0 un attaquant de\nprovoquer une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 09 mai 2024",
          "url": "https://www.postgresql.org/about/news/postgresql-163-157-1412-1315-and-1219-released-2858/"
        }
      ]
    }

    CERTFR-2024-AVI-0157

    Vulnerability from certfr_avis - Published: 2024-02-22 - Updated: 2024-02-22

    Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elles permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.6.x versions antérieures à 42.6.1
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.3.x versions antérieures à 42.3.9
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.2.x versions antérieures à 42.2.28 et 42.2.28.jre7
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.5.x versions antérieures à 42.5.5
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.7.x versions antérieures à 42.7.2
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.4.x versions antérieures à 42.4.4

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL JDBC versions 42.6.x versions ant\u00e9rieures \u00e0 42.6.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.3.x versions ant\u00e9rieures \u00e0 42.3.9",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.2.x versions ant\u00e9rieures \u00e0 42.2.28 et 42.2.28.jre7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.5.x versions ant\u00e9rieures \u00e0 42.5.5",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.7.x versions ant\u00e9rieures \u00e0 42.7.2",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.4.x versions ant\u00e9rieures \u00e0 42.4.4",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2024-1597",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-1597"
        }
      ],
      "initial_release_date": "2024-02-22T00:00:00",
      "last_revision_date": "2024-02-22T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0157",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-02-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL JDBC. Elles permet \u00e0\nun attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL JDBC",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL JDBC GHSA-24rp-q3w6-vc56 du 21 f\u00e9vrier 2024",
          "url": "https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 21 f\u00e9vrier 2024",
          "url": "https://www.postgresql.org/about/news/postgresql-jdbc-4272-4261-4255-4244-4239-42228-and-42228jre7-security-update-for-cve-2024-1597-2812/"
        }
      ]
    }

    CERTFR-2024-AVI-0111

    Vulnerability from certfr_avis - Published: 2024-02-09 - Updated: 2024-02-09

    Une vulnérabilité a été découverte dans PostgreSQL. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.18
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.14
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.11
    PostgreSQL PostgreSQL PostgreSQL versions 16.x antérieures à 16.2
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.18",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.14",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.11",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 16.x ant\u00e9rieures \u00e0 16.2",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.6",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2024-0985",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-0985"
        }
      ],
      "initial_release_date": "2024-02-09T00:00:00",
      "last_revision_date": "2024-02-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0111",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-02-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans \u003cspan\nclass=\"textit\"\u003ePostgreSQL\u003c/span\u003e. Elle permet \u00e0 un attaquant de\nprovoquer une ex\u00e9cution de code arbitraire \u00e0 distance\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 08 f\u00e9vrier 2024",
          "url": "https://www.postgresql.org/about/news/postgresql-162-156-1411-1314-and-1218-released-2807/"
        }
      ]
    }

    CERTFR-2023-AVI-0651

    Vulnerability from certfr_avis - Published: 2023-08-11 - Updated: 2023-08-11

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécution de code arbitraire et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 11.x antérieures à 11.21
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.9
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.12
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.16
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.4
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 11.x ant\u00e9rieures \u00e0 11.21",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.9",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.12",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.16",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.4",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-39417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39417"
        },
        {
          "name": "CVE-2023-39418",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39418"
        }
      ],
      "initial_release_date": "2023-08-11T00:00:00",
      "last_revision_date": "2023-08-11T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0651",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-08-11T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Elles\npermettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire\net un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 10 ao\u00fbt 2023",
          "url": "https://www.postgresql.org/about/news/postgresql-154-149-1312-1216-1121-and-postgresql-16-beta-3-released-2689/"
        }
      ]
    }

    CERTFR-2023-AVI-0378

    Vulnerability from certfr_avis - Published: 2023-05-12 - Updated: 2023-05-12

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.11
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.8
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.15
    PostgreSQL PostgreSQL PostgreSQL versions antérieures à 11.20
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.3
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.11",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.8",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.15",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions ant\u00e9rieures \u00e0 11.20",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.3",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-2454",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2454"
        },
        {
          "name": "CVE-2023-2455",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-2455"
        }
      ],
      "initial_release_date": "2023-05-12T00:00:00",
      "last_revision_date": "2023-05-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0378",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-05-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL. Elles\npermettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire\n\u00e0 distance, une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es et une atteinte \u00e0 la\nconfidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL released-2637 du 11 mai 2023",
          "url": "https://www.postgresql.org/about/news/postgresql-153-148-1311-1215-and-1120-released-2637/"
        }
      ]
    }

    CERTFR-2023-AVI-0107

    Vulnerability from certfr_avis - Published: 2023-02-09 - Updated: 2023-02-09

    Une vulnérabilité a été corrigée dans PostgreSQL. Elle permet à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 15.x antérieures à 15.2
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.10
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.7
    PostgreSQL PostgreSQL PostgreSQL versions 11.x antérieures à 11.19
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.14

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 15.x ant\u00e9rieures \u00e0 15.2",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.10",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 11.x ant\u00e9rieures \u00e0 11.19",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.14",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-41862",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41862"
        }
      ],
      "initial_release_date": "2023-02-09T00:00:00",
      "last_revision_date": "2023-02-09T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 09 f\u00e9vrier 2023",
          "url": "https://www.postgresql.org/about/news/postgresql-152-147-1310-1214-and-1119-released-2592/"
        }
      ],
      "reference": "CERTFR-2023-AVI-0107",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-02-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans \u003cspan\nclass=\"textit\"\u003ePostgreSQL\u003c/span\u003e. Elle permet \u00e0 un attaquant de\nprovoquer un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la\nconfidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL CVE-2022-41862 du 09 f\u00e9vrier 2023",
          "url": null
        }
      ]
    }

    CERTFR-2022-AVI-1054

    Vulnerability from certfr_avis - Published: 2022-11-24 - Updated: 2022-11-24

    Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.5.x antérieures à 42.5.1
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.4.x antérieures à 42.4.3
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.3.x antérieures à 42.3.8
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.2.x antérieures à 42.2.27.jre7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL JDBC versions 42.5.x ant\u00e9rieures \u00e0 42.5.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.4.x ant\u00e9rieures \u00e0 42.4.3",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.3.x ant\u00e9rieures \u00e0 42.3.8",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.2.x ant\u00e9rieures \u00e0 42.2.27.jre7",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-41946",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41946"
        }
      ],
      "initial_release_date": "2022-11-24T00:00:00",
      "last_revision_date": "2022-11-24T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-1054",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-11-24T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL JDBC. Elle permet \u00e0\nun attaquant de provoquer une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL JDBC",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 23 novembre 2022",
          "url": "https://www.postgresql.org/about/news/postgresql-jdbc-4251-4243-4238-42227jre7-security-update-for-cve-2022-41946-2551/"
        }
      ]
    }

    CERTFR-2022-AVI-743

    Vulnerability from certfr_avis - Published: 2022-08-16 - Updated: 2022-08-16

    Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL JDBC versions antérieures à 42.2.26
    PostgreSQL PostgreSQL PostgreSQL JDBC versions 42.3.x et 42.4.x antérieures à 42.4.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL JDBC versions ant\u00e9rieures \u00e0 42.2.26",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL JDBC versions 42.3.x et 42.4.x ant\u00e9rieures \u00e0 42.4.1",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-31197",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-31197"
        }
      ],
      "initial_release_date": "2022-08-16T00:00:00",
      "last_revision_date": "2022-08-16T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-743",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-08-16T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans PostgreSQL JDBC. Elle permet \u00e0\nun attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans PostgreSQL JDBC",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL du 15 ao\u00fbt 2022",
          "url": "https://www.postgresql.org/about/news/postgresql-jdbc-versions-424142226-security-update-2492/"
        }
      ]
    }

    CERTFR-2022-AVI-739

    Vulnerability from certfr_avis - Published: 2022-08-12 - Updated: 2022-08-12

    De multiples vulnérabilités ont été découvertes dans PostgreSQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PostgreSQL PostgreSQL PostgreSQL versions 13.x antérieures à 13.8
    PostgreSQL PostgreSQL PostgreSQL versions 10.x antérieures à 10.22
    PostgreSQL PostgreSQL PostgreSQL versions 14.x antérieures à 14.5
    PostgreSQL PostgreSQL PostgreSQL versions 11.x antérieures à 11.17
    PostgreSQL PostgreSQL PostgreSQL versions 12.x antérieures à 12.12
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PostgreSQL versions 13.x ant\u00e9rieures \u00e0 13.8",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 10.x ant\u00e9rieures \u00e0 10.22",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 14.x ant\u00e9rieures \u00e0 14.5",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 11.x ant\u00e9rieures \u00e0 11.17",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        },
        {
          "description": "PostgreSQL versions 12.x ant\u00e9rieures \u00e0 12.12",
          "product": {
            "name": "PostgreSQL",
            "vendor": {
              "name": "PostgreSQL",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-1552",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-1552"
        },
        {
          "name": "CVE-2022-2625",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-2625"
        }
      ],
      "initial_release_date": "2022-08-12T00:00:00",
      "last_revision_date": "2022-08-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-739",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-08-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PostgreSQL.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PostgreSQL",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PostgreSQL 2496 du 11 ao\u00fbt 2022",
          "url": "https://www.postgresql.org/about/news/postgresql-145-138-1212-1117-1022-and-15-beta-3-released-2496/"
        }
      ]
    }

    CVE-2024-10979 (GCVE-0-2024-10979)

    Vulnerability from cvelistv5 – Published: 2024-11-14 13:00 – Updated: 2025-11-03 21:51
    VLAI
    Title
    PostgreSQL PL/Perl environment variable changes execute arbitrary code
    Summary
    Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-20 00:00 UTC
    CWE
    • CWE-15 - External Control of System or Configuration Setting
    Impacted products
    Vendor Product Version
    n/a PostgreSQL Affected: 17 , < 17.1 (rpm)
    Affected: 16 , < 16.5 (rpm)
    Affected: 15 , < 15.9 (rpm)
    Affected: 14 , < 14.14 (rpm)
    Affected: 13 , < 13.17 (rpm)
    Affected: 0 , < 12.21 (rpm)
    postgresql postgresql Affected: 0 , < 12.21 (rpm)
    Affected: 13 , < 13.17 (rpm)
    Affected: 14 , < 14.14 (rpm)
    Affected: 15 , < 15.9 (rpm)
    Affected: 16 , < 16.5 (rpm)
    Affected: 17 , < 17.1 (rpm)
        cpe:2.3:a:postgresql:postgresql:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:postgresql:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "postgresql",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThan": "12.21",
                    "status": "affected",
                    "version": "0",
                    "versionType": "rpm"
                  },
                  {
                    "lessThan": "13.17",
                    "status": "affected",
                    "version": "13",
                    "versionType": "rpm"
                  },
                  {
                    "lessThan": "14.14",
                    "status": "affected",
                    "version": "14",
                    "versionType": "rpm"
                  },
                  {
                    "lessThan": "15.9",
                    "status": "affected",
                    "version": "15",
                    "versionType": "rpm"
                  },
                  {
                    "lessThan": "16.5",
                    "status": "affected",
                    "version": "16",
                    "versionType": "rpm"
                  },
                  {
                    "lessThan": "17.1",
                    "status": "affected",
                    "version": "17",
                    "versionType": "rpm"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10979",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-20T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-21T04:55:16.916Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T21:51:41.330Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://github.com/fmora50591/postgresql-env-vuln/blob/main/README.md"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250110-0003/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00011.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "PostgreSQL",
              "vendor": "n/a",
              "versions": [
                {
                  "lessThan": "17.1",
                  "status": "affected",
                  "version": "17",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "16.5",
                  "status": "affected",
                  "version": "16",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "15.9",
                  "status": "affected",
                  "version": "15",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "14.14",
                  "status": "affected",
                  "version": "14",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "13.17",
                  "status": "affected",
                  "version": "13",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "12.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "value": "administrator has installed PL/Perl"
            },
            {
              "lang": "en",
              "value": "attacker has permission to create objects (temporary objects or non-temporary objects in at least one schema)"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "The PostgreSQL project thanks Coby Abrams for reporting this problem."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH).  That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user.  Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-15",
                  "description": "External Control of System or Configuration Setting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-14T13:00:08.586Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "url": "https://www.postgresql.org/support/security/CVE-2024-10979/"
            }
          ],
          "title": "PostgreSQL PL/Perl environment variable changes execute arbitrary code"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-10979",
        "datePublished": "2024-11-14T13:00:08.586Z",
        "dateReserved": "2024-11-07T19:27:04.476Z",
        "dateUpdated": "2025-11-03T21:51:41.330Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-9014 (GCVE-0-2024-9014)

    Vulnerability from cvelistv5 – Published: 2024-09-23 17:04 – Updated: 2024-09-23 19:21
    VLAI
    Title
    OAuth2 client id and secret exposed through the web browser in pgAdmin 4
    Summary
    pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-23 19:13 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    References
    Impacted products
    Vendor Product Version
    pgadmin.org pgAdmin 4 Affected: 0 , < 8.12 (custom)
    Create a notification for this product.
    postgresql pgadmin_4 Affected: 0 , < 8.12 (custom)
        cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "pgadmin_4",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThan": "8.12",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9014",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-23T19:13:55.230423Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-522",
                    "description": "CWE-522 Insufficiently Protected Credentials",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-23T19:21:22.348Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "User Authentication"
              ],
              "product": "pgAdmin 4",
              "programFiles": [
                "https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/templates/security/login_user.html"
              ],
              "repo": "https://github.com/pgadmin-org/pgadmin4",
              "vendor": "pgadmin.org",
              "versions": [
                {
                  "lessThan": "8.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-23T17:04:00.264Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pgadmin-org/pgadmin4/issues/7945"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "OAuth2 client id and secret exposed through the web browser in pgAdmin 4",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-9014",
        "datePublished": "2024-09-23T17:04:00.264Z",
        "dateReserved": "2024-09-19T18:00:05.741Z",
        "dateUpdated": "2024-09-23T19:21:22.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7348 (GCVE-0-2024-7348)

    Vulnerability from cvelistv5 – Published: 2024-08-08 13:00 – Updated: 2024-08-22 18:03
    VLAI
    Title
    PostgreSQL relation replacement during pg_dump executes arbitrary SQL
    Summary
    Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-15 00:00 UTC
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    n/a PostgreSQL Affected: 16 , < 16.4 (rpm)
    Affected: 15 , < 15.8 (rpm)
    Affected: 14 , < 14.13 (rpm)
    Affected: 13 , < 13.16 (rpm)
    Affected: 0 , < 12.20 (rpm)
    postgresql postgresql Affected: 0 , < 12.20 (custom)
    Affected: 13 , < 13.16 (custom)
    Affected: 14 , < 14.13 (custom)
    Affected: 15 , < 15.8 (custom)
    Affected: 16 , < 16.4 (custom)
        cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "postgresql",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThan": "12.20",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "13.16",
                    "status": "affected",
                    "version": "13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "14.13",
                    "status": "affected",
                    "version": "14",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "15.8",
                    "status": "affected",
                    "version": "15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "16.4",
                    "status": "affected",
                    "version": "16",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7348",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-15T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-16T04:01:38.124Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-22T18:03:18.699Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2024/08/11/1"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20240822-0002/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "PostgreSQL",
              "vendor": "n/a",
              "versions": [
                {
                  "lessThan": "16.4",
                  "status": "affected",
                  "version": "16",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "15.8",
                  "status": "affected",
                  "version": "15",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "14.13",
                  "status": "affected",
                  "version": "14",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "13.16",
                  "status": "affected",
                  "version": "13",
                  "versionType": "rpm"
                },
                {
                  "lessThan": "12.20",
                  "status": "affected",
                  "version": "0",
                  "versionType": "rpm"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "value": "attacker has permission to create non-temporary objects in at least one schema"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "The PostgreSQL project thanks Noah Misch for reporting this problem."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-08T13:00:02.130Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "url": "https://www.postgresql.org/support/security/CVE-2024-7348/"
            }
          ],
          "title": "PostgreSQL relation replacement during pg_dump executes arbitrary SQL"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-7348",
        "datePublished": "2024-08-08T13:00:02.130Z",
        "dateReserved": "2024-07-31T18:33:23.341Z",
        "dateUpdated": "2024-08-22T18:03:18.699Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-4216 (GCVE-0-2024-4216)

    Vulnerability from cvelistv5 – Published: 2024-05-02 17:42 – Updated: 2025-02-13 17:53
    VLAI
    Title
    XSS vulnerability in /settings/store API response json payload in pgAdmin 4
    Summary
    pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-06 16:28 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    pgadmin.org pgAdmin 4 Affected: 0 , < 8.6 (custom)
    Create a notification for this product.
    postgresql pgadmin Affected: 0 , ≤ 8.5 (custom)
        cpe:2.3:a:postgresql:pgadmin:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-07 18:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:pgadmin:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "pgadmin",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThanOrEqual": "8.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4216",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-06T16:28:06.753868Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-79",
                    "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-06T17:41:23.683Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:33:52.902Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://github.com/pgadmin-org/pgadmin4/issues/7282"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2YFVCB4HCXU3FQBZ5XTWJZWSZUDNCXE/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "pgadmin layout"
              ],
              "product": "pgAdmin 4",
              "programFiles": [
                "https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/browser/templates/browser/js/utils.js"
              ],
              "repo": "https://github.com/pgadmin-org/pgadmin4",
              "vendor": "pgadmin.org",
              "versions": [
                {
                  "lessThan": "8.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-07T18:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003epgAdmin \u0026lt;= 8.5 is affected by \u0026nbsp;XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "pgAdmin \u003c= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T17:11:21.501Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pgadmin-org/pgadmin4/issues/7282"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2YFVCB4HCXU3FQBZ5XTWJZWSZUDNCXE/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "XSS vulnerability in /settings/store API response json payload in pgAdmin 4",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-4216",
        "datePublished": "2024-05-02T17:42:59.679Z",
        "dateReserved": "2024-04-25T20:53:44.444Z",
        "dateUpdated": "2025-02-13T17:53:31.153Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-4215 (GCVE-0-2024-4215)

    Vulnerability from cvelistv5 – Published: 2024-05-02 17:42 – Updated: 2025-02-13 17:53
    VLAI
    Title
    The Multi Factor Authentication bypass vulnerability in pgAdmin 4
    Summary
    pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA enrollment status.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-02 20:13 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    pgadmin.org pgAdmin 4 Affected: 0 , < 8.6 (custom)
    Create a notification for this product.
    postgresql pgadmin Affected: 0 , ≤ 8.5 (custom)
        cpe:2.3:a:postgresql:pgadmin:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-07 18:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:pgadmin:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "pgadmin",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThanOrEqual": "8.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-4215",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-02T20:13:31.339220Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-24T21:00:52.725Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:33:52.916Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://github.com/pgadmin-org/pgadmin4/issues/7425"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2YFVCB4HCXU3FQBZ5XTWJZWSZUDNCXE/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "Login Module"
              ],
              "product": "pgAdmin 4",
              "repo": "https://github.com/pgadmin-org/pgadmin4",
              "vendor": "pgadmin.org",
              "versions": [
                {
                  "lessThan": "8.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-07T18:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003epgAdmin \u0026lt;= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account\u2019s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account\u2019s MFA enrollment status.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "pgAdmin \u003c= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account\u2019s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account\u2019s MFA enrollment status."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T17:11:19.748Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pgadmin-org/pgadmin4/issues/7425"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2YFVCB4HCXU3FQBZ5XTWJZWSZUDNCXE/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "The Multi Factor Authentication bypass vulnerability in pgAdmin 4",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-4215",
        "datePublished": "2024-05-02T17:42:34.880Z",
        "dateReserved": "2024-04-25T20:53:43.801Z",
        "dateUpdated": "2025-02-13T17:53:30.480Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-3116 (GCVE-0-2024-3116)

    Vulnerability from cvelistv5 – Published: 2024-04-04 14:59 – Updated: 2025-03-14 16:35
    VLAI
    Title
    Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
    Summary
    pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-04 16:40 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    pgadmin.org pgAdmin 4 Affected: 0 , < 8.5 (custom)
    Create a notification for this product.
    postgresql pgadmin_4 Affected: 0 , < 8.5 (custom)
        cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-07 18:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-19T07:47:48.299Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://github.com/pgadmin-org/pgadmin4/issues/7326"
              },
              {
                "tags": [
                  "mitigation",
                  "x_transferred"
                ],
                "url": "https://gist.github.com/aelmokhtar/689a8be7e3bd535ec01992d8ec7b2b98"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIF5T34JTTYRGIN5YPT366BDFG6452A2/"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/remote-code-execution-vulnerability-in-pgadmin-cve-2024-3116"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "pgadmin_4",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThan": "8.5",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-3116",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-04T16:40:01.024525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-14T16:35:25.051Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "Utility\u0027s Binary Path"
              ],
              "product": "pgAdmin 4",
              "programFiles": [
                "https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/misc/__init__.py"
              ],
              "repo": "https://github.com/pgadmin-org/pgadmin4",
              "vendor": "pgadmin.org",
              "versions": [
                {
                  "lessThan": "8.5",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-07T18:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003epgAdmin \u0026lt;= 8.4 is affected by a  Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system\u0027s integrity and the security of the underlying data.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "pgAdmin \u003c= 8.4 is affected by a  Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system\u0027s integrity and the security of the underlying data."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-23T02:06:21.997Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pgadmin-org/pgadmin4/issues/7326"
            },
            {
              "tags": [
                "mitigation"
              ],
              "url": "https://gist.github.com/aelmokhtar/689a8be7e3bd535ec01992d8ec7b2b98"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIF5T34JTTYRGIN5YPT366BDFG6452A2/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-3116",
        "datePublished": "2024-04-04T14:59:37.280Z",
        "dateReserved": "2024-03-30T03:46:32.060Z",
        "dateUpdated": "2025-03-14T16:35:25.051Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-2044 (GCVE-0-2024-2044)

    Vulnerability from cvelistv5 – Published: 2024-03-07 20:48 – Updated: 2025-02-13 17:32
    VLAI
    Title
    Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
    Summary
    pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-11 14:48 UTC
    CWE
    • CWE-31 - Path Traversal: 'dir\..\..\filename'
    Impacted products
    Vendor Product Version
    pgadmin.org pgAdmin 4 Affected: 0 , < 8.4 (custom)
    Create a notification for this product.
    postgresql pgadmin_4 Affected: 0 , < 8.4 (custom)
        cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fedoraproject fedora Affected: 40
        cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-07 18:30
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:pgadmin_4:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "pgadmin_4",
                "vendor": "postgresql",
                "versions": [
                  {
                    "lessThan": "8.4",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fedora",
                "vendor": "fedoraproject",
                "versions": [
                  {
                    "status": "affected",
                    "version": "40"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2044",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-11T14:48:18.333654Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-31",
                    "description": "CWE-31 Path Traversal: \u0027dir\\..\\..\\filename\u0027",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-26T14:01:32.203Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:03:37.856Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://github.com/pgadmin-org/pgadmin4/issues/7258"
              },
              {
                "tags": [
                  "mitigation",
                  "x_transferred"
                ],
                "url": "https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LUYN2JXKKHFSVTASH344TBRGWDH64XQV/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "User Session"
              ],
              "product": "pgAdmin 4",
              "programFiles": [
                "https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/utils/session.py"
              ],
              "repo": "https://github.com/pgadmin-org/pgadmin4",
              "vendor": "pgadmin.org",
              "versions": [
                {
                  "lessThan": "8.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-03-07T18:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003epgAdmin \u0026lt;= 8.3 is affected by a path-traversal vulnerability while deserializing users\u2019 sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "pgAdmin \u003c= 8.3 is affected by a path-traversal vulnerability while deserializing users\u2019 sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-23T02:06:24.688Z",
            "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
            "shortName": "PostgreSQL"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/pgadmin-org/pgadmin4/issues/7258"
            },
            {
              "tags": [
                "mitigation"
              ],
              "url": "https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LUYN2JXKKHFSVTASH344TBRGWDH64XQV/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "assignerShortName": "PostgreSQL",
        "cveId": "CVE-2024-2044",
        "datePublished": "2024-03-07T20:48:10.066Z",
        "dateReserved": "2024-02-29T23:14:12.007Z",
        "dateUpdated": "2025-02-13T17:32:31.782Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-24213 (GCVE-0-2024-24213)

    Vulnerability from cvelistv5 – Published: 2024-02-08 00:00 – Updated: 2024-08-19 19:55 Disputed
    VLAI
    Summary
    Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 19:54 UTC
    CWE
    • n/a
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    postgresql postgresql Affected: 15.1
        cpe:2.3:a:postgresql:postgresql:15.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T23:19:51.989Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://app.flows.sh:8443/project/default%2C"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://reference1.example.com/project/default/logs/explorer%2C"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://postfixadmin.ballardini.com.ar:8443/project/default/logs/explorer."
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/940198871/Vulnerability-details/blob/main/CVE-2024-24213"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://supabase.com/docs/guides/database/overview#the-sql-editor"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:postgresql:postgresql:15.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "postgresql",
                "vendor": "postgresql",
                "versions": [
                  {
                    "status": "affected",
                    "version": "15.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-24213",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T19:54:51.515234Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T19:55:59.420Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor\u0027s position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-05T01:15:47.086Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://app.flows.sh:8443/project/default%2C"
            },
            {
              "url": "https://reference1.example.com/project/default/logs/explorer%2C"
            },
            {
              "url": "https://postfixadmin.ballardini.com.ar:8443/project/default/logs/explorer."
            },
            {
              "url": "https://github.com/940198871/Vulnerability-details/blob/main/CVE-2024-24213"
            },
            {
              "url": "https://supabase.com/docs/guides/database/overview#the-sql-editor"
            }
          ],
          "tags": [
            "disputed"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-24213",
        "datePublished": "2024-02-08T00:00:00.000Z",
        "dateReserved": "2024-01-25T00:00:00.000Z",
        "dateUpdated": "2024-08-19T19:55:59.420Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }