9.8
CVSSv3

CVE-2018-16850

Published: 13/11/2018 Updated: 19/01/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

postgresql prior to 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

redhat enterprise linux 7.4

redhat enterprise linux 7.0

redhat enterprise linux 7.5

redhat enterprise linux 7.6

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Synopsis Important: rh-postgresql10-postgresql security update Type/Severity Security Advisory: Important Topic An update for rh-postgresql10-postgresql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
PostgreSQL could be made to run SQL statements as the administrator ...
A SQL Injection flaw has been discovered in PostgreSQL server in the way triggers that enable transition relations are dumped The transition relation name is not correctly quoted and it may allow an attacker with CREATE privilege on some non-temporary schema or TRIGGER privilege on some table to create a malicious trigger that, when dumped and res ...
For more information about PostgreSQL versioning, please visit the versioning page ...