First published: Wed May 24 2023(Updated: )
Alexander Lakhin discovered that PostgreSQL incorrectly handled certain CREATE privileges. An authenticated user could possibly use this issue to execute arbitrary code as the bootstrap supervisor. (CVE-2023-2454) Wolfgang Walther discovered that PostgreSQL incorrectly handled certain row security policies. An authenticated user could possibly use this issue to complete otherwise forbidden reads and modifications. (CVE-2023-2455)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/postgresql-15 | <15.3-0ubuntu0.23.04.1 | 15.3-0ubuntu0.23.04.1 |
=23.04 | ||
All of | ||
ubuntu/postgresql-client-15 | <15.3-0ubuntu0.23.04.1 | 15.3-0ubuntu0.23.04.1 |
=23.04 | ||
All of | ||
ubuntu/postgresql-14 | <14.8-0ubuntu0.22.10.1 | 14.8-0ubuntu0.22.10.1 |
=22.10 | ||
All of | ||
ubuntu/postgresql-client-14 | <14.8-0ubuntu0.22.10.1 | 14.8-0ubuntu0.22.10.1 |
=22.10 | ||
All of | ||
ubuntu/postgresql-14 | <14.8-0ubuntu0.22.04.1 | 14.8-0ubuntu0.22.04.1 |
=22.04 | ||
All of | ||
ubuntu/postgresql-client-14 | <14.8-0ubuntu0.22.04.1 | 14.8-0ubuntu0.22.04.1 |
=22.04 | ||
All of | ||
ubuntu/postgresql-12 | <12.15-0ubuntu0.20.04.1 | 12.15-0ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/postgresql-client-12 | <12.15-0ubuntu0.20.04.1 | 12.15-0ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/postgresql-10 | <10.23-0ubuntu0.18.04.2 | 10.23-0ubuntu0.18.04.2 |
=18.04 | ||
All of | ||
ubuntu/postgresql-client-10 | <10.23-0ubuntu0.18.04.2 | 10.23-0ubuntu0.18.04.2 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for these PostgreSQL vulnerabilities is CVE-2023-2454.
The severity of CVE-2023-2454 is not specified.
An attacker can exploit CVE-2023-2454 by executing arbitrary code as the bootstrap supervisor.
Versions 15.3-0ubuntu0.23.04.1, 14.8-0ubuntu0.22.10.1, 14.8-0ubuntu0.22.04.1, 12.15-0ubuntu0.20.04.1, and 10.23-0ubuntu0.18.04.2 of PostgreSQL are affected by CVE-2023-2454.
You can find more information about these PostgreSQL vulnerabilities on the Ubuntu Security Notices page.