« List of all CVEs

CVE-2023-39417

Postgresql: extension script @substitutions@ within quoting allow sql injection

Published: 8/11/2023 Last updated: 3/2/2026 Reserved: 8/1/2023

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.5 High CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (5)

conf-mingw-w64-postgresql-i686 conf-mingw-w64-postgresql-x86_64 conf-postgresql ocsigen-start postgresql

Products affected (29)

Product Vendor Version
RHACS-4.1-RHEL-8 Red Hat < 6.1.7601.27219
RHACS-4.1-RHEL-8 Red Hat < 18.8.4
RHACS-3.74-RHEL-8 Red Hat < 500.1.1.6 ( 2024/08/02 )
RHACS-3.74-RHEL-8 Red Hat <= 11022026
Red Hat Advanced Cluster Security 4.2 Red Hat Genoa++_1.0.0.H
RHACS-4.1-RHEL-8 Red Hat < 10.0.19044.4651
RHACS-3.74-RHEL-8 Red Hat < 10.0.22631.3880
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.17763.6054
RHACS-4.1-RHEL-8 Red Hat < 10.0.17763.6054
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.19045.4651
RHACS-3.74-RHEL-8 Red Hat < 10.0.14393.7159
Red Hat Enterprise Linux 6 Red Hat < 10.0.19044.4651
Red Hat Enterprise Linux 7 Red Hat < 10.0.25398.1009
Red Hat Enterprise Linux 8 Red Hat < 10.0.14393.7159
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat < 6.2.9200.24975
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat < 10.0.14393.7159
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat < 6.3.9600.22074
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < 10.0.14393.7159
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat < 1.2.11
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat < 10.0.22631.3880
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < 6.2.9200.24975
Red Hat Enterprise Linux 8 Red Hat < 6.2.9200.24975
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat < 10.0.17763.6054
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat < 1.17.7
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat < 10.0.22631.3880
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < 6.2.9200.24975
Red Hat Software Collections Red Hat SAP_BASIS 752
Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat < 10.0.20348.2582
Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat < 6.1.7601.27219

References (104)