8.8
CVE-2024-10979
- EPSS 6.1%
- Veröffentlicht 14.11.2024 13:15:04
- Zuletzt bearbeitet 11.02.2025 21:27:49
- Quelle f86ef6dc-4d3a-42ad-8f28-e6d554
- Teams Watchlist Login
- Unerledigt Login
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 12.0 < 12.21
Postgresql ≫ Postgresql Version >= 13.0 < 13.17
Postgresql ≫ Postgresql Version >= 14.0 < 14.14
Postgresql ≫ Postgresql Version >= 15.0 < 15.9
Postgresql ≫ Postgresql Version >= 16.0 < 16.5
Postgresql ≫ Postgresql Version >= 17.0 < 17.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.1% | 0.904 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-15 External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
CWE-610 Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.