CloudNativePG是CloudNativePG开源的一个在Kubernetes上管理PostgreSQL数据库全生命周期的开源平台。 CloudNativePG 1.29.1之前版本和1.28.3之前版本存在代码问题漏洞,该漏洞源于指标导出器通过pod本地Unix套接字以postgres超级用户身份打开PostgreSQL连接,然后使用SET ROLE pg_monitor降级会话,但session_user仍为postgres,攻击者可在抓取会话中调用RESET ROLE恢复超级用户权限,并使用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cloudnative-pg | cloudnative-pg | < 1.28.3 |
affected |
>= 1.29.0, < 1.29.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cloudnative-pg | cloudnative-pg | < 1.28.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet