VDB
CVE-2022-2625
CVE-2022-2625
PUBLISHED
CVSS 8 HIGH
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
EPSS 1.91% · 78.9th percentile
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.91%
78.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | postgresql | 10.0.0, 12.0.0, 13.0.0 |
| Bitnami | postgresql | 11.0.0, 12.0.0, 13.0.0 |
Timeline
- Apr 30, 2017 PoC Published
- Jun 28, 2021 PoC Published
- Apr 22, 2022 PoC Published
- Aug 11, 2022 CVE Published
- Aug 19, 2022 EPSS Score
- Oct 4, 2022 EPSS Score
- Nov 19, 2022 EPSS Score
- Feb 20, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 23, 2023 EPSS Score
- Jun 9, 2023 PoC Published