7.5
CVSSv2

CVE-2021-33204

Published: 19/05/2021 Updated: 07/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In the pg_partman (aka PG Partition Manager) extension prior to 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pgxn pg partman

Vendor Advisories

Debian Bug report logs - #988917 pg-partman: CVE-2021-33204 Package: src:pg-partman; Maintainer for src:pg-partman is Debian PostgreSQL Maintainers <team+postgresql@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 21 May 2021 12:03:04 UTC Severity: grave Tags: security, upstream ...