VDB
CVE-2020-14349
CVE-2020-14349
PUBLISHED
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
EPSS 1.55% · 81.7th percentile
Risk Scores
EPSS Score
1.55%
81.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | postgresql | 10.0.0, 11.0.0, 12.0.0 |
| Bitnami | postgresql | 10.0.0, 11.0.0, 12.0.0 |
Timeline
- Aug 14, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=1865744 url
- https://security.gentoo.org/glsa/202008-13 url
- https://security.netapp.com/advisory/ntap-20200918-0002/ url
- https://usn.ubuntu.com/4472-1/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-14349 url