First published: Fri May 12 2023(Updated: )
CVE-2023-2454: CREATE SCHEMA ... schema_element defeats protective search_path changes. Versions Affected: 11 - 15. This problem is quite old. This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. <a href="https://www.postgresql.org/support/security/CVE-2023-2454/">https://www.postgresql.org/support/security/CVE-2023-2454/</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/PostgreSQL | <15.3 | 15.3 |
redhat/PostgreSQL | <14.8 | 14.8 |
redhat/PostgreSQL | <13.11 | 13.11 |
redhat/PostgreSQL | <12.15 | 12.15 |
redhat/PostgreSQL | <11.20 | 11.20 |
PostgreSQL PostgreSQL | >=11.0<11.20 | |
PostgreSQL PostgreSQL | >=12.0<12.15 | |
PostgreSQL PostgreSQL | >=13.0<13.11 | |
PostgreSQL PostgreSQL | >=14.0<14.8 | |
PostgreSQL PostgreSQL | >=15.0<15.3 | |
Redhat Software Collections | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =9.0 | |
Fedoraproject Fedora | =38 | |
ubuntu/postgresql-10 | <10.23-0ubuntu0.18.04.2 | 10.23-0ubuntu0.18.04.2 |
ubuntu/postgresql-12 | <12.15-0ubuntu0.20.04.1 | 12.15-0ubuntu0.20.04.1 |
ubuntu/postgresql-14 | <14.8-0ubuntu0.22.04.1 | 14.8-0ubuntu0.22.04.1 |
ubuntu/postgresql-14 | <14.8-0ubuntu0.22.10.1 | 14.8-0ubuntu0.22.10.1 |
ubuntu/postgresql-15 | <15.3-0ubuntu0.23.04.1 | 15.3-0ubuntu0.23.04.1 |
ubuntu/postgresql-9.5 | <9.5.25-0ubuntu0.16.04.1+ | 9.5.25-0ubuntu0.16.04.1+ |
debian/postgresql-11 | <=11.16-0+deb10u1 | 11.22-0+deb10u2 |
debian/postgresql-13 | 13.13-0+deb11u1 13.14-0+deb11u1 | |
debian/postgresql-15 | 15.5-0+deb12u1 15.6-0+deb12u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2454 is high (7).
CVE-2023-2454 can permit an authenticated attacker with elevated database-level privileges to execute arbitrary code in PostgreSQL.
CVE-2023-2454 affects PostgreSQL versions 9.5, 10, 11, 12, 13, 14, and 15.
To fix CVE-2023-2454 in PostgreSQL, update to the latest available version and apply any necessary patches.
You can find more information about CVE-2023-2454 at the following references: [1] [2] [3]