{"id":"CVE-2020-14350","year":2020,"sequence":14350,"component":"core server","score":7.1,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","first_published":"2020-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2020-14350/","facts":{"affected":{"10":"10","11":"11","12":"12","9.5":"9.5","9.6":"9.6"},"component":"core server","cvss_version":"3.0","description_en":"When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable.\n\nIn addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work.\n\nThe PostgreSQL project thanks Andres Freund for reporting this problem.","first_published":"2020-08-13","fixed":{"10":"10.14","11":"11.9","12":"12.4","9.5":"9.5.23","9.6":"9.6.19"},"id":"CVE-2020-14350","introduced":{},"published":{"10":"2020-08-13","11":"2020-08-13","12":"2020-08-13","9.5":"2020-08-13","9.6":"2020-08-13"},"score":7.1,"title":"Uncontrolled search path element in CREATE EXTENSION","url":"https://www.postgresql.org/support/security/CVE-2020-14350/","vector":"AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"Uncontrolled search path element in CREATE EXTENSION","description":"When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable.\n\nIn addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work.\n\nThe PostgreSQL project thanks Andres Freund for reporting this problem.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"f7be900699c2c03d9450346fe876f3b201b481855316fc104ea8d77311232be1"},"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.14","introduced":null,"published_date":"2020-08-13","facts":{"fixed":"10.14","introduced":null,"published":"2020-08-13"}},{"major":"11","fixed_version":"11.9","introduced":null,"published_date":"2020-08-13","facts":{"fixed":"11.9","introduced":null,"published":"2020-08-13"}},{"major":"12","fixed_version":"12.4","introduced":null,"published_date":"2020-08-13","facts":{"fixed":"12.4","introduced":null,"published":"2020-08-13"}},{"major":"9.5","fixed_version":"9.5.23","introduced":null,"published_date":"2020-08-13","facts":{"fixed":"9.5.23","introduced":null,"published":"2020-08-13"}},{"major":"9.6","fixed_version":"9.6.19","introduced":null,"published_date":"2020-08-13","facts":{"fixed":"9.6.19","introduced":null,"published":"2020-08-13"}}],"legacy":[]}
