漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path`
Vulnerability Description
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create overloaded built-in operators in the public schema and change the database or role search_path, causing instance-manager introspection queries such as SELECT COUNT(*) > 0 FROM pg_catalog.pg_extension WHERE extname = $1 to execute attacker-controlled functions as the postgres superuser. The same trust issue affected direct sql.Open("pgx", ...) callsites and the public.user_search SECURITY DEFINER function, enabling PostgreSQL superuser access, operating system command execution through COPY ... FROM PROGRAM, and access to the pod ServiceAccount token. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
CloudNativePG 权限许可和访问控制问题漏洞
Vulnerability Description
CloudNativePG是CloudNativePG团队的一款消息队列中间件。 CloudNativePG 1.28.4之前版本和1.29.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在pkg/management/postgres/pool/profiles.go的fillDefaultParameters中未固定search_path,可能导致具有数据库所有者权限的角色创建重载的内置运算符并更改搜索路径,从而以postgres超级用户执行攻击者控制的函数,实现操作系统命令执行和访问pod S
CVSS Information
N/A
Vulnerability Type
N/A