Korean
<< Back
VID 25331
Severity 30
Port 5432
Protocol TCP
Class DB
Detailed Description The version of PostgreSQL installed on the remote host is 9.5 prior to 9.5.23, 9.6 prior to 9.6.19, 10 prior to 10.14, 11 prior to 11.9, or 12 prior to 12.4. As such, it is potentially affected by multiple vulnerabilities :

- Uncontrolled search path element in logical replication (CVE-2020-14349)

- Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350)

* References:
https://www.postgresql.org/about/news/2060/
https://access.redhat.com/security/cve/CVE-2020-14349
https://access.redhat.com/security/cve/CVE-2020-14350

* Platforms Affected:
PostgreSQL 9.5.x prior to 9.5.23
Any operating system Any version
Recommendation Upgrade to the latest version of PostgreSQL (9.5.23 or later), available from the PostgreSQL Web page at http://www.postgresql.org/download/
Related URL CVE-2020-14349,CVE-2020-14350 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)