CVE-2020-25695 is a high-severity privilege escalation flaw affecting PostgreSQL versions prior to 13.1, 12.5, 11.10, 10.15, 9.6.20, and 9.5.24. An authenticated attacker with object creation permissions in any schema can execute arbitrary SQL functions as a superuser, leading to significant impacts on data confidentiality, integrity, and system availability. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low privileges and no user interaction. While no public exploit code is currently available in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.5.24CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 9.6.0, < 9.6.20CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.15CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.10CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.5CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
postgresql: Multiple features escape "security restricted operation" sandbox
Nov 12, 2020A flaw was found in PostgreSQL versions before 13.1 before 12.5 before 11.10 before 10.15 before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Nov 10, 2020