ZeroHour

CVE-2018-1058

CVSS 3.1
8.8 high
EPSS
13%p96
Published
()
Modified
Description

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

Vendors
postgresqlcanonicalredhat
Products
postgresql, ubuntu linux, cloudforms
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.