CVE-2023-2454
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Version Information
| Affected branch | Introduced | Fixed In | Fix Published |
|---|---|---|---|
| 11 | — | 11.20 | 2023-05-11 |
| 12 | — | 12.15 | 2023-05-11 |
| 13 | — | 13.11 | 2023-05-11 |
| 14 | — | 14.8 | 2023-05-11 |
| 15 | — | 15.3 | 2023-05-11 |
CVSS 3.0
| Overall Score | 7.2 |
|---|---|
| Component | core server |
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
First published: 2023-05-11
Historical source observations
These dated records preserve the original source claims separately from the reviewed fix list.
center · 2026-10-03 12:08:35.169032+08
- PostgreSQL 15 · Original minor coordinate: 3
- PostgreSQL 14 · Original minor coordinate: 8
pgweb · 2026-10-03 12:08:55.967155+08
- PostgreSQL 15 · Original minor coordinate: 3
- PostgreSQL 14 · Original minor coordinate: 8