Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-1713
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plv8 Deferred Trigger Privilege Escalation
Source: NVD (National Vulnerability Database)
Vulnerability Description
A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未预期的状态编码或返回值
Source: NVD (National Vulnerability Database)
Vulnerability Title
Plv8 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Plv8是一个共享库,提供由 V8 Javascript 引擎支持的 PostgreSQL 过程语言。 Plv8 3.2.1版本存在安全漏洞,该漏洞源于数据库中创建对象的用户能够在autovacuum期间以超级用户身份执行延迟触发器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Plv8Plv8 3.2.1 -
II. Public POCs for CVE-2024-1713
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-1713
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-1713

No comments yet


Leave a comment