CVE-2017-16082: Code Injection
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
Other sources
Affected versions of pg contain a remote code execution vulnerability that occurs when the remote database or query specifies a crafted column name.
There are two specific scenarios in which it is likely for an application to be vulnerable: 1. The application executes unsafe, user-supplied sql which contains malicious column names. 2. The application connects to an untrusted database and executes a query returning results which contain a malicious column name.
Proof of Concept const { Client } = require('pg') const client = new Client() client.connect()
const sql = SELECT 1 AS "\\'/", 2 AS "\\'/\n + console.log(process.env)] = null;\n//"
client.query(sql, (err, res) => { client.end() })
Recommendation
Version 2.x.x: Update to version 2.11.2 or later. Version 3.x.x: Update to version 3.6.4 or later. Version 4.x.x: Update to version 4.5.7 or later. Version 5.x.x: Update to version 5.2.1 or later. Version 6.x.x: Update to version 6.4.2 or later. ( Note that versions 6.1.6, 6.2.5, and 6.3.3 are also patched. ) Version 7.x.x: Update to version 7.1.2 or later. ( Note that version 7.0.2 is also patched. )
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16082?
CVE-2017-16082 is classified as a high severity vulnerability due to its remote code execution capabilities.
How do I fix CVE-2017-16082?
To fix CVE-2017-16082, upgrade to pg versions 7.1.2, 7.0.2, 6.4.2, or 6.3.3 or later.
What causes CVE-2017-16082?
CVE-2017-16082 is caused by the processing of specially crafted column names in user-supplied SQL queries.
Which systems are affected by CVE-2017-16082?
CVE-2017-16082 affects versions of the pg module in Node.js from 2.0.0 to 7.1.1.
How can I test for CVE-2017-16082 in my application?
You can test for CVE-2017-16082 by running SQL queries that utilize unsafe, user-supplied column names to check for unexpected behavior.