CVE-2018-16850 PUBLISHED

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

EPSS 1.32% · 79.8th percentile

Risk Scores

EPSS Score
1.32%
79.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpostgresql-100, 10.1-1, 10.1-2

Timeline

References

Open in Interactive Console →