pgcollection 是 PostgreSQL 的一个开源扩展。AWS pgcollection 2.0.0 至 2.1.1 版本中存在类型混淆漏洞,攻击者可通过精心构造的 SQL 语句利用集合值检索和数组转换函数中不匹配的类型元数据,在已认证远程用户身份下以 postgres 操作系统用户权限执行任意代码。 为修复此问题,建议用户升级至 2.1.2 或更高版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | pgcollection | 2.0.0≤ 2.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | pgcollection | 2.0.0 ~ 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet