CVE-2022-1552
Summary
| CVE | CVE-2022-1552 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-31 16:15:00 UTC |
| Updated | 2023-11-07 03:42:00 UTC |
| Description | A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 2081126 – (CVE-2022-1552) CVE-2022-1552 postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| PostgreSQL: CVE-2022-1552: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox |
MISC |
www.postgresql.org |
|
| PostgreSQL: Multiple Vulnerabilities (GLSA 202211-04) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| PostgreSQL: PostgreSQL 14.3, 13.7, 12.11, 11.16, and 10.21 Released! |
MISC |
www.postgresql.org |
|
| CVE-2022-1552 PostgreSQL Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159873 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2022-4807)
- 159875 Oracle Enterprise Linux Security Update for postgresql:10 (ELSA-2022-4805)
- 159876 Oracle Enterprise Linux Security Update for postgresql:13 (ELSA-2022-4855)
- 159911 Oracle Enterprise Linux Security Update for postgresql (ELSA-2022-5162)
- 159929 Oracle Enterprise Linux Security Update for postgresql (ELSA-2022-4771)
- 179278 Debian Security Update for postgresql-13 (DSA 5136-1)
- 179279 Debian Security Update for postgresql-11 (DSA 5135-1)
- 198800 Ubuntu Security Notification for PostgreSQL Vulnerability (USN-5440-1)
- 240373 Red Hat Update for postgresql:10 (RHSA-2022:4805)
- 240374 Red Hat Update for postgresql (RHSA-2022:4771)
- 240385 Red Hat Update for postgresql:12 (RHSA-2022:4807)
- 240395 Red Hat Update for postgresql:10 (RHSA-2022:4854)
- 240396 Red Hat Update for postgresql:13 (RHSA-2022:4857)
- 240398 Red Hat Update for postgresql:12 (RHSA-2022:4856)
- 240400 Red Hat Update for postgresql:13 (RHSA-2022:4855)
- 240403 Red Hat Update for postgresql:10 (RHSA-2022:4895)
- 240404 Red Hat Update for postgresql:12 (RHSA-2022:4893)
- 240412 Red Hat Update for rh-postgresql10-postgresql (RHSA-2022:4913)
- 240413 Red Hat Update for rh-postgresql12-postgresql (RHSA-2022:4915)
- 240417 Red Hat Update for rh-postgresql13-postgresql (RHSA-2022:4929)
- 240481 Red Hat Update for postgresql (RHSA-2022:5162)
- 257178 CentOS Security Update for postgresql (CESA-2022:5162)
- 354062 Amazon Linux Security Advisory for postgresql : ALAS2-2022-1843
- 354295 Amazon Linux Security Advisory for postgresql14 : ALAS2022-2022-124
- 354340 Amazon Linux Security Advisory for postgresql14 : ALAS2022-2022-190
- 356214 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL14-2023-002
- 356234 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL13-2023-002
- 356286 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL11-2023-002
- 356301 Amazon Linux Security Advisory for libpq : ALASPOSTGRESQL12-2023-003
- 356306 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-002
- 356468 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL11-2023-002
- 356472 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL12-2023-002
- 356487 Amazon Linux Security Advisory for libpq : ALAS2POSTGRESQL12-2023-003
- 376922 Alibaba Cloud Linux Security Update for postgresql:13 (ALINUX3-SA-2022:0136)
- 377059 Alibaba Cloud Linux Security Update for postgresql (ALINUX2-SA-2022:0026)
- 501473 Alpine Linux Security Update for postgresql
- 501996 Alpine Linux Security Update for postgresql13
- 502013 Alpine Linux Security Update for postgresql14
- 502159 Alpine Linux Security Update for postgresql12
- 502779 Alpine Linux Security Update for postgresql15
- 504312 Alpine Linux Security Update for postgresql14
- 505671 Alpine Linux Security Update for postgresql15
- 672040 EulerOS Security Update for postgresql (EulerOS-SA-2022-2231)
- 672071 EulerOS Security Update for postgresql (EulerOS-SA-2022-2278)
- 672215 EulerOS Security Update for postgresql (EulerOS-SA-2022-2631)
- 690867 Free Berkeley Software Distribution (FreeBSD) Security Update for postgresql server (157ce083-d145-11ec-ab9b-6cc21735f730)
- 710683 Gentoo Linux PostgreSQL Multiple Vulnerabilities (GLSA 202211-04)
- 752165 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2022:1804-1)
- 752172 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2022:1835-1)
- 752182 SUSE Enterprise Linux Security Update for postgresql14 (SUSE-SU-2022:1874-1)
- 752183 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2022:1869-1)
- 752193 SUSE Enterprise Linux Security Update for postgresql13 (SUSE-SU-2022:1895-1)
- 752197 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2022:1890-1)
- 752198 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2022:1894-1)
- 752199 SUSE Enterprise Linux Security Update for postgresql14 (SUSE-SU-2022:1908-1)
- 752505 SUSE Enterprise Linux Security Update for postgresql10 (SUSE-SU-2022:2893-1)
- 752529 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2022:2958-1)
- 903751 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (10817)
- 903806 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (10826)
- 904162 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (10826-1)
- 904176 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (10817-1)
- 940584 AlmaLinux Security Update for postgresql:10 (ALSA-2022:4805)
- 940588 AlmaLinux Security Update for postgresql:12 (ALSA-2022:4807)
- 960204 Rocky Linux Security Update for postgresql:10 (RLSA-2022:4805)
- 960240 Rocky Linux Security Update for postgresql:13 (RLSA-2022:4855)
- 960429 Rocky Linux Security Update for postgresql:12 (RLSA-2022:4807)
- 960600 Rocky Linux Security Update for postgresql (RLSA-2022:4771)