↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2023-2454

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
11—11.202023-05-11
12—12.152023-05-11
13—13.112023-05-11
14—14.82023-05-11
15—15.32023-05-11

CVSS 3.0

Overall Score7.2
Componentcore server
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

First published: 2023-05-11

Historical source observations

These dated records preserve the original source claims separately from the reviewed fix list.

center · 2026-10-03 12:08:35.169032+08

  • PostgreSQL 15 · Original minor coordinate: 3
  • PostgreSQL 14 · Original minor coordinate: 8

pgweb · 2026-10-03 12:08:55.967155+08

  • PostgreSQL 15 · Original minor coordinate: 3
  • PostgreSQL 14 · Original minor coordinate: 8

Original security advisory · JSON · All advisories