↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2020-25696

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.152020-11-12
11—11.102020-11-12
12—12.52020-11-12
13—13.12020-11-12
9.5—9.5.242020-11-12
9.6—9.6.202020-11-12

CVSS 3.0

Overall Score7.5
Componentclient
VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

First published: 2020-11-12

Original security advisory · JSON · All advisories