漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod
Vulnerability Description
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was preloaded with track_utility enabled and an untrusted tenant held pg_monitor or pg_read_all_stats, the tenant could recover platform-managed superuser or application-owner passwords, reconnect through enabled superuser TCP access, and execute operating system commands in the database pod with `COPY ... FROM PROGRAM`. Clusters using SCRAM-SHA-256 verifiers in managed-role Secrets were not affected. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
明文存储口令
Vulnerability Title
CloudNativePG 信任管理问题漏洞
Vulnerability Description
CloudNativePG是CloudNativePG团队的一款消息队列中间件。 CloudNativePG 1.28.4之前版本和1.29.0至1.29.2之前版本存在信任管理问题漏洞,该漏洞源于在ALTER ROLE和CREATE ROLE语句中嵌入明文角色密码,且pg_stat_statements预加载并启用track_utility时,具有pg_monitor或pg_read_all_stats权限的不可信租户可恢复平台管理的超级用户或应用所有者密码,进而通过超级用户TCP访问执行操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A