V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-25696
AST
High

A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.…

CVSS
7.5
High
EPSS
0.00
p65
Published
2020-01-01
Updated
2020-01-01
Description

A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Tags · CWE
Pre-auth
CWE-183
CAPEC-3
CAPEC-43
CAPEC-71
CAPEC-120
Affected products
LibpqLibpqLibpqLibpqPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresqlPostgresql-10Postgresql-11Postgresql-11Postgresql-11Postgresql-12Postgresql-12
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.005 · p65
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
libpqTracked
libpqTracked
libpqTracked
libpqTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresqlTracked
postgresql-10Tracked
postgresql-11Tracked
postgresql-11Tracked
postgresql-11Tracked
postgresql-12Tracked
postgresql-12Tracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities