postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.
Version | Score | Severity | Vector String |
---|---|---|---|
3.0 | 8 | High | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Product | Vendor | Version |
---|---|---|
postgresql | The PostgreSQL Project | ettercap 0.7.5 |