CVE-2022-1552 is a high-severity vulnerability in PostgreSQL that allows an authenticated attacker to execute arbitrary SQL functions as a superuser. This flaw stems from insufficient protection during maintenance operations (e.g., Autovacuum, REINDEX) when a privileged user manages another user's objects. With a CVSS score of 8.8, this vulnerability presents a significant risk of complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for a low-complexity network-based attack by an authenticated user makes it a critical concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, < 10.21CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.16CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.11CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.7CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.3CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-1552
Sep 13, 2022A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum REINDEX CREATE INDEX REFRESH MATERIALIZED VIEW CLUSTER and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
Aug 9, 2022postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
May 12, 2022Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Jan 1, 2022Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox