VDB

CVE-2017-16082

CVE-2017-16082 PUBLISHED

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

EPSS 70.82% · 98.7th percentile

Risk Scores

EPSS Score
70.82%
98.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSnode-postgres0.13.3-1, 0

Timeline

  • Jun 7, 2018 CVE Published
  • Oct 9, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 3, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
  • Apr 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›