CVE-2023-39417
Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Related CPE's
References
Vendor Advisory
Third Party Advisory
Issue TrackingThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics