Description
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5135-1 | postgresql-11 security update |
Debian DSA |
DSA-5136-1 | postgresql-13 security update |
EUVD |
EUVD-2022-24847 | A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity. |
Ubuntu USN |
USN-5440-1 | PostgreSQL vulnerability |
Ubuntu USN |
USN-5676-1 | PostgreSQL vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T00:10:03.498Z
Reserved: 2022-05-02T00:00:00.000Z
Link: CVE-2022-1552
No data.
Status : Modified
Published: 2022-08-31T16:15:09.867
Modified: 2024-11-21T06:40:57.223
Link: CVE-2022-1552
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN