Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-10979

PostgreSQL: PL/Perl environment variable changes allow code execution

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21 (11 not assessed)

Upstream Fix

17.1; 16.5; 15.9; 14.14; 13.17; 12.21

Published

November 14, 2024

OSSeva Coverage

Fixed upstream

Description

PL/Perl did not control changes to process environment variables, so an unprivileged database user could change sensitive ones such as PATH. That often suffices for arbitrary code execution, even when the attacker has no operating system account on the database server. Fixed in 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21 (11 not assessed), you need this patch. Book a discovery call to get covered.