schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
2023-06-09T19:15:09.253
2025-01-06T18:15:13.670
Modified
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | postgresql | postgresql | < 11.20 | Yes |
Application | postgresql | postgresql | < 12.15 | Yes |
Application | postgresql | postgresql | < 13.11 | Yes |
Application | postgresql | postgresql | < 14.8 | Yes |
Application | postgresql | postgresql | < 15.3 | Yes |
Application | redhat | software_collections | - | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |