CVE-2019-9193

Related Vulnerabilities: CVE-2019-9193  

Impact: Important Public Date: 2019-03-20 CWE: CWE-20 Bugzilla: 1695982: CVE-2019-9193 postgresql: Command injection via "COPY TO/FROM PROGRAM" function In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_read_server_files' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS.

The MITRE CVE dictionary describes this issue as:

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_read_server_files' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS.

Find out more about CVE-2019-9193 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 rh-postgresql95-postgresql Under investigation
Red Hat Virtualization 4 postgresql Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-postgresql10-postgresql Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-postgresql95-postgresql Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-postgresql96-postgresql Under investigation
Red Hat Satellite 5 rh-postgresql95-postgresql Under investigation
Red Hat Enterprise Linux 7 postgresql Under investigation
Red Hat Enterprise Linux 6 postgresql Under investigation
Red Hat Enterprise Linux 5 postgresql Under investigation
Red Hat Ansible Tower 3 for RHEL 7 postgresql96-libs Under investigation