USN-6104-1: PostgreSQL vulnerabilities
Alexander Lakhin discovered that PostgreSQL incorrectly handled certain CREATE privileges. An authenticated user could possibly use this issue to execute arbitrary code as the bootstrap supervisor. (CVE-2023-2454) Wolfgang Walther discovered that PostgreSQL incorrectly handled certain row security policies. An authenticated user could possibly use this issue to complete otherwise forbidden reads and modifications. (CVE-2023-2455)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for these PostgreSQL vulnerabilities?
The vulnerability ID for these PostgreSQL vulnerabilities is CVE-2023-2454.
What is the severity of CVE-2023-2454?
The severity of CVE-2023-2454 is not specified.
How can an attacker exploit CVE-2023-2454?
An attacker can exploit CVE-2023-2454 by executing arbitrary code as the bootstrap supervisor.
Which versions of PostgreSQL are affected by CVE-2023-2454?
Versions 15.3-0ubuntu0.23.04.1, 14.8-0ubuntu0.22.10.1, 14.8-0ubuntu0.22.04.1, 12.15-0ubuntu0.20.04.1, and 10.23-0ubuntu0.18.04.2 of PostgreSQL are affected by CVE-2023-2454.
Where can I find more information about these PostgreSQL vulnerabilities?
You can find more information about these PostgreSQL vulnerabilities on the Ubuntu Security Notices page.