schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2023-2454 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20230706-0006/ | |
https://www.postgresql.org/support/security/CVE-2023-2454/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2023-06-09 19:15
Updated : 2023-07-06 19:15
NVD link : CVE-2023-2454
Mitre link : CVE-2023-2454
CVE.ORG link : CVE-2023-2454
JSON object : View
Products Affected
fedoraproject
- fedora
postgresql
- postgresql
redhat
- enterprise_linux
- software_collections
CWE