CVE-2020-14349

HIGH

PostgreSQL 10.0-10.13 - Authenticated SQL Injection via Logical Replication Search Path

Title source: llm
STIX 2.1

Description

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

References (9)

Core 9
Core References
Broken Link, Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.html
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1865744
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202008-13
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4472-1/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200918-0002/

Scores

CVSS v3 7.1
EPSS 0.0155
EPSS Percentile 81.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427 CWE-89
Status published
Products (3)
opensuse/leap 15.1
opensuse/leap 15.2
postgresql/postgresql 10.0 - 10.14
Published Aug 24, 2020
Tracked Since Feb 18, 2026