CVE-2023-23554: High severity cisco prime infrastructure vulnerability
Uncontrolled search path element vulnerability exists in pgivm versions prior to 1.5.1. When refreshing an IMMV, pgivm executes functions without specifying schema names. Under certain conditions, pgivm may be tricked to execute unexpected functions from other schemas with the IMMV owner's privilege. If this vulnerability is exploited, an unexpected function provided by an attacker may be executed with the privilege of the materialized view owner.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23554?
CVE-2023-23554 is classified as a high severity vulnerability due to its potential for arbitrary function execution.
How do I fix CVE-2023-23554?
To fix CVE-2023-23554, upgrade pg_ivm to version 1.5.1 or later.
What are the potential impacts of CVE-2023-23554?
CVE-2023-23554 may allow an attacker to execute unexpected functions from other schemas, leading to unauthorized access or data manipulation.
Which versions of pg_ivm are affected by CVE-2023-23554?
CVE-2023-23554 affects pg_ivm versions prior to 1.5.1.
Who is affected by CVE-2023-23554?
Users of pg_ivm versions below 1.5.1 running on PostgreSQL are affected by CVE-2023-23554.