Postgresql: extension script @substitutions@ within quoting allow sql injection
Summary
| CVE | CVE-2023-39417 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-11 13:15:09 UTC |
| Updated | 2026-09-30 20:17:12 UTC |
| Description | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-89 | CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Advanced Cluster Security 4.2 | unaffected 4.2.4-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Security 4.2 | unaffected 4.2.4-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Security 4.2 | unaffected 4.2.4-7 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Security 4.2 | unaffected 4.2.4-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Security 4.2 | unaffected 4.2.4-7 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8090020231114113712.a75119d5 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8090020231128173330.a75119d5 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8090020231114113548.a75119d5 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 8020020231128165246.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | unaffected 8020020231128165246.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Update Services For SAP Solutions | unaffected 8020020231128165246.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 8040020231127153301.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 8040020231127154806.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 8040020231127153301.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 8040020231127154806.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 8040020231127153301.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 8040020231127154806.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | unaffected 8060020231114115246.ad008a3a * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | unaffected 8060020231128165328.ad008a3a * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 8080020231114105206.63b34585 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 8080020231128165335.63b34585 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | unaffected 8080020231113134015.63b34585 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:13.13-1.el9_3 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 9030020231120082734.rhel9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 0:13.13-1.el9_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 0:13.13-1.el9_2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | unaffected 9020020231115020618.rhel9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Software Collections For Red Hat Enterprise Linux 7 | unaffected 0:12.17-1.el7 * rpm | Not specified |
| CNA | Red Hat | Red Hat Software Collections For Red Hat Enterprise Linux 7 | unaffected 0:13.13-1.el7 * rpm | Not specified |
| CNA | Red Hat | RHACS-3.74-RHEL-8 | unaffected 3.74.8-9 * rpm | Not specified |
| CNA | Red Hat | RHACS-3.74-RHEL-8 | unaffected 3.74.8-9 * rpm | Not specified |
| CNA | Red Hat | RHACS-3.74-RHEL-8 | unaffected 3.74.8-7 * rpm | Not specified |
| CNA | Red Hat | RHACS-3.74-RHEL-8 | unaffected 3.74.8-9 * rpm | Not specified |
| CNA | Red Hat | RHACS-3.74-RHEL-8 | unaffected 3.74.8-9 * rpm | Not specified |
| CNA | Red Hat | RHACS-4.1-RHEL-8 | unaffected 4.1.6-6 * rpm | Not specified |
| CNA | Red Hat | RHACS-4.1-RHEL-8 | unaffected 4.1.6-6 * rpm | Not specified |
| CNA | Red Hat | RHACS-4.1-RHEL-8 | unaffected 4.1.6-6 * rpm | Not specified |
| CNA | Red Hat | RHACS-4.1-RHEL-8 | unaffected 4.1.6-6 * rpm | Not specified |
| CNA | Red Hat | RHACS-4.1-RHEL-8 | unaffected 4.1.6-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Software Collections | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3600-1] postgresql-11 security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| PostgreSQL: CVE-2023-39417: Extension script @substitutions@ within quoting allow SQL injection | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| 2228111 – (CVE-2023-39417) CVE-2023-39417 postgresql: extension script @substitutions@ within quoting allow SQL injection | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Debian -- Security Information -- DSA-5553-1 postgresql-15 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| lists.debian.org/debian-lts-announce/2026/09/msg00039.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Debian -- Security Information -- DSA-5554-1 postgresql-13 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| August 2023 PostgreSQL Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-08-01T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-08-10T00:00:00.000Z | Made public. |
Legacy QID Mappings
- 161207 Oracle Enterprise Linux Security Update for postgresql:13 (ELSA-2023-7581)
- 161232 Oracle Enterprise Linux Security Update for postgresql:15 (ELSA-2023-7785)
- 161242 Oracle Enterprise Linux Security Update for postgresql (ELSA-2023-7784)
- 161250 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2023-7714)
- 161253 Oracle Enterprise Linux Security Update for postgresql:15 (ELSA-2023-7884)
- 199665 Ubuntu Security Notification for PostgreSQL Vulnerabilities (USN-6296-1)
- 242527 Red Hat Update for postgresql (RHSA-2023:7545)
- 242534 Red Hat Update for postgresql:13 (RHSA-2023:7580)
- 242536 Red Hat Update for postgresql:13 (RHSA-2023:7581)
- 242537 Red Hat Update for postgresql:13 (RHSA-2023:7579)
- 242540 Red Hat Update for postgresql (RHSA-2023:7616)
- 242544 Red Hat Update for postgresql:12 (RHSA-2023:7656)
- 242546 Red Hat Update for postgresql:12 (RHSA-2023:7666)
- 242547 Red Hat Update for postgresql:12 (RHSA-2023:7667)
- 242550 Red Hat Update for postgresql:13 (RHSA-2023:7695)
- 242552 Red Hat Update for postgresql:12 (RHSA-2023:7694)
- 242558 Red Hat Update for postgresql:12 (RHSA-2023:7714)
- 242591 Red Hat Update for rh-postgresql12-postgresql (RHSA-2023:7770)
- 242592 Red Hat Update for rh-postgresql13-postgresql (RHSA-2023:7772)
- 242611 Red Hat Update for postgresql (RHSA-2023:7784)
- 242614 Red Hat Update for postgresql:15 (RHSA-2023:7785)
- 242634 Red Hat Update for postgresql:15 (RHSA-2023:7885)
- 242636 Red Hat Update for postgresql:15 (RHSA-2023:7883)
- 242657 Red Hat Update for postgresql:15 (RHSA-2023:7884)
- 356204 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL14-2023-003
- 356250 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL11-2023-004
- 356257 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-005
- 356308 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL13-2023-004
- 356473 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL12-2023-005
- 356492 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL11-2023-004
- 379115 Alibaba Cloud Linux Security Update for postgresql:13 (ALINUX3-SA-2023:0139)
- 379588 Gitlab Multiple Vulnerabilities (prior to gitlab- 16.6.1, 16.5.3, 16.4.3)
- 503280 Alpine Linux Security Update for postgresql
- 503281 Alpine Linux Security Update for postgresql13
- 503282 Alpine Linux Security Update for postgresql14
- 503283 Alpine Linux Security Update for postgresql12
- 503284 Alpine Linux Security Update for postgresql15
- 505920 Alpine Linux Security Update for postgresql15
- 506163 Alpine Linux Security Update for postgresql13
- 506165 Alpine Linux Security Update for postgresql14
- 6000141 Debian Security Update for postgresql-11 (DLA 3600-1)
- 6000321 Debian Security Update for postgresql-13 (DSA 5554-1)
- 6000322 Debian Security Update for postgresql-15 (DSA 5553-1)
- 673920 EulerOS Security Update for postgresql (EulerOS-SA-2023-3146)
- 691228 Free Berkeley Software Distribution (FreeBSD) Security Update for postgresql (cfd2a634-3785-11ee-94b4-6cc21735f730)
- 754277 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3343-1)
- 754278 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3342-1)
- 754279 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2023:3341-1)
- 754282 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2023:3346-1)
- 754283 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3345-1)
- 907731 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (27892-1)
- 941485 AlmaLinux Security Update for postgresql:13 (ALSA-2023:7581)
- 941501 AlmaLinux Security Update for postgresql (ALSA-2023:7784)
- 941508 AlmaLinux Security Update for postgresql:12 (ALSA-2023:7714)
- 941510 AlmaLinux Security Update for postgresql:15 (ALSA-2023:7785)
- 941512 AlmaLinux Security Update for postgresql:15 (ALSA-2023:7884)
- 961088 Rocky Linux Security Update for postgresql:13 (RLSA-2023:7581)