V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-0060
DEB
Medium

PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce th…

CVSS
5.5
Medium
EPSS
0.04
p89
Published
2014-01-01
Updated
2014-01-01
Description

PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.

Tags · CWE
CWE-264
Affected products
Postgresql ≤ 8.4.19Postgresql
CVSS vector
AV:N/AC:L/Au:S/C:N/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: S
Single
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.041 · p89
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cfmeTracked
postgresqlTracked
postgresqlTracked
postgresql-8.4Tracked
postgresql-8.4Tracked
postgresql-9.1Tracked
postgresql-9.1Tracked
postgresql-9.3Tracked
postgresql-9.3Tracked
postgresql84Tracked
postgresql92-postgresqlTracked
postgresql92-postgresqlTracked
princeTracked
ruby193-rubygem-actionpackTracked
postgresql*Tracked
Source databases
DEB
CVE
RED
UBU