Vulnerability Name: | CVE-2020-10733 | ||||||||||||
Assigned: | 2020-09-16 | ||||||||||||
Published: | 2020-09-16 | ||||||||||||
Updated: | 2022-01-06 | ||||||||||||
Summary: | The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-426 | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-10733 Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20201001-0006/ Source: MISC Type: Vendor Advisory https://www.postgresql.org/about/news/2038/ Source: MISC Type: Vendor Advisory https://www.postgresql.org/support/security/11/ | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Vulnerability Name: | CVE-2020-10733 (CCN-188396) | ||||||||||||
Assigned: | 2020-08-13 | ||||||||||||
Published: | 2020-08-13 | ||||||||||||
Updated: | 2020-10-01 | ||||||||||||
Summary: | The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-426 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-10733 Source: XF Type: UNKNOWN postgresql-cve202010733-code-exec(188396) Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20201001-0006/ Source: CCN Type: IBM Security Bulletin 6456209 (Connect:Direct Web Services) Security Bypass Vulnerability in PostgreSQL Affects IBM Connect:Direct Web Services (CVE-2020-10733) Source: CCN Type: PostgreSQL Web site PostgreSQL 12.3, 11.8, 10.13, 9.6.18, and 9.5.22 Released! Source: MISC Type: Vendor Advisory https://www.postgresql.org/about/news/2038/ Source: MISC Type: Vendor Advisory https://www.postgresql.org/support/security/11/ | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |