CVE-2024-10979
PostgreSQL: PL/Perl environment variable changes allow code execution
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21 (11 not assessed)
Upstream Fix
17.1; 16.5; 15.9; 14.14; 13.17; 12.21
Published
November 14, 2024
OSSeva Coverage
Fixed upstream
Description
PL/Perl did not control changes to process environment variables, so an unprivileged database user could change sensitive ones such as PATH. That often suffices for arbitrary code execution, even when the attacker has no operating system account on the database server. Fixed in 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21.
Is your PostgreSQL deployment affected?
If you're running Before 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21 (11 not assessed), you need this patch. Book a discovery call to get covered.