CVE Published: 11/08/2023 |
CVE Updated: 15/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Advanced Cluster Security 4.2 Status : PUBLISHED
CVE-2023-39417 Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, \'\', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.