↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2020-25695

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.152020-11-12
11—11.102020-11-12
12—12.52020-11-12
13—13.12020-11-12
9.5—9.5.242020-11-12
9.6—9.6.202020-11-12

CVSS 3.0

Overall Score8.8
Componentcore server
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

First published: 2020-11-12

Original security advisory · JSON · All advisories