漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
aiven-extras allows PostgreSQL Privilege Escalation through format function
Vulnerability Description
aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should install 1.1.16 and ensure they run the latest version issuing ALTER EXTENSION aiven_extras UPDATE TO '1.1.16' after installing it. This needs to happen in each database aiven_extras has been installed in.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
aiven-extras 代码问题漏洞
Vulnerability Description
aiven-extras是aiven开源的一个能让非超级用户能够使用某些数据库功能的工具。 aiven-extras 1.1.15之前版本存在代码问题漏洞,该漏洞源于格式函数未使用模式前缀,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A