« List of all CVEs

CVE-2023-39417

Postgresql: extension script @substitutions@ within quoting allow sql injection

Published: 8/11/2023 Last updated: 3/12/2026 Reserved: 8/1/2023

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.5 High CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (5)

conf-mingw-w64-postgresql-i686 conf-mingw-w64-postgresql-x86_64 conf-postgresql ocsigen-start postgresql

Products affected (37)

Product Vendor Version
RHACS-4.1-RHEL-8 Red Hat < 6.0.6003.23418
RHACS-3.74-RHEL-8 Red Hat < 10.0.26100.4652
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.14393.8330
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.14393.8330
RHACS-3.74-RHEL-8 Red Hat -
RHACS-3.74-RHEL-8 Red Hat < 10.0.10240.20978
RHACS-4.1-RHEL-8 Red Hat < 10.0.17763.7136
RHACS-3.74-RHEL-8 Red Hat < 10.0.19044.5371
RHACS-4.1-RHEL-8 Red Hat < 6.0.6003.23418
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.17763.7678
RHACS-3.74-RHEL-8 Red Hat < 6.1.7601.27820
RHACS-3.74-RHEL-8 Red Hat < 10.0.25398.1369
RHACS-3.74-RHEL-8 Red Hat < 10.0.14393.7969
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.17763.7678
RHACS-4.1-RHEL-8 Red Hat < 10.0.19044.5737
RHACS-3.74-RHEL-8 Red Hat < 6.1.7601.27820
RHACS-4.1-RHEL-8 Red Hat < 6.2.9200.25573
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.20348.4052
RHACS-4.1-RHEL-8 Red Hat < 10.0.22631.5039
Red Hat Advanced Cluster Security 4.2 Red Hat < 10.0.10240.20890
Red Hat Enterprise Linux 6 Red Hat < 10.0.19045.5737
Red Hat Enterprise Linux 7 Red Hat < 6.2.9200.25573
Red Hat Enterprise Linux 7 Red Hat < 6.3.9600.22470
Red Hat Enterprise Linux 8 Red Hat < 10.0.17763.7009
Red Hat Enterprise Linux 8 Red Hat < 10.0.22621.5189
Red Hat Enterprise Linux 8 Red Hat < 10.0.26100.4946
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat < 6.3.9600.22371
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat < 6.2.9200.25622
Red Hat Enterprise Linux 8 Red Hat < 10.0.22631.4751
Red Hat Enterprise Linux 8 Red Hat < 10.0.19044.5371
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat < 10.0.22631.4890
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat < 10.0.14393.7785
Red Hat Enterprise Linux 8 Red Hat < 10.0.25398.1791
Red Hat Enterprise Linux 8 Red Hat < 6.1.7601.27520
Red Hat Enterprise Linux 8 Red Hat < 10.0.26100.4946
Red Hat Software Collections Red Hat < 6.3.9600.22676
Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Fixed in curl 7.87.0

References (104)