CVE-2022-2625
postgresql-11 - security update
8.0
HIGH
CVSS 3.1
EPSS 1.5%
描述
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
如何修補 CVE-2022-2625
要修補 CVE-2022-2625,請將受影響套件升級到下列已修補版本。
- —升級至 13.8-r0 或更新版本
- —升級至 13.8-r0 或更新版本
- —升級至 14.5-r0 或更新版本
- —升級至 14.5-r0 或更新版本
CVE-2022-2625 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- >= 10.0, < 13.8-r0
- from 0, < 13.8-r0
- from 0, < 14.5-r0
- from 0, < 14.5-r0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |