{"id":"CVE-2022-1552","year":2022,"sequence":1552,"component":"core server","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2022-05-12","source_url":"https://www.postgresql.org/support/security/CVE-2022-1552/","facts":{"affected":{"10":"10","11":"11","12":"12","13":"13","14":"14"},"component":"core server","cvss_version":"3.0","description_en":"Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity.\n\nWhile promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object.\n\nThe PostgreSQL project thanks Alexander Lakhin for reporting this problem.","first_published":"2022-05-12","fixed":{"10":"10.21","11":"11.16","12":"12.11","13":"13.7","14":"14.3"},"id":"CVE-2022-1552","introduced":{},"published":{"10":"2022-05-12","11":"2022-05-12","12":"2022-05-12","13":"2022-05-12","14":"2022-05-12"},"score":8.8,"title":"Autovacuum, REINDEX, and others omit \"security restricted operation\" sandbox","url":"https://www.postgresql.org/support/security/CVE-2022-1552/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","description":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2022-1552","cvenumber":202201552,"description":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2022-1552","id":29,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":29,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2022-1552","cvenumber":202201552,"description":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2022-1552","id":29,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":29,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"f47f63aecd1b53674c3dff75012e3ced6328efe7a20a110fd97523155249fc78"},"locales":["en","zh-Hans"],"fixes":[{"major":"10","fixed_version":"10.21","introduced":null,"published_date":"2022-05-12","facts":{"fixed":"10.21","introduced":null,"published":"2022-05-12"}},{"major":"11","fixed_version":"11.16","introduced":null,"published_date":"2022-05-12","facts":{"fixed":"11.16","introduced":null,"published":"2022-05-12"}},{"major":"12","fixed_version":"12.11","introduced":null,"published_date":"2022-05-12","facts":{"fixed":"12.11","introduced":null,"published":"2022-05-12"}},{"major":"13","fixed_version":"13.7","introduced":null,"published_date":"2022-05-12","facts":{"fixed":"13.7","introduced":null,"published":"2022-05-12"}},{"major":"14","fixed_version":"14.3","introduced":null,"published_date":"2022-05-12","facts":{"fixed":"14.3","introduced":null,"published":"2022-05-12"}}],"legacy":[{"source":"center","source_id":29,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":29,"cve":"2022-1552","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202201552,"description":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","detailslink":"https://access.redhat.com/security/cve/CVE-2022-1552","legacyscore":"","newspost_id":null},"fixes":[{"source_id":96,"source_version_id":27,"major":"14","fixed_minor":3,"raw":{"id":96,"patch_id":29,"version_id":27,"fixed_minor":3},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":29,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":29,"cve":"2022-1552","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"core server","cvenumber":202201552,"description":"Autovacuum、REINDEX 等操作遗漏了 security restricted operation 沙箱","detailslink":"https://access.redhat.com/security/cve/CVE-2022-1552","legacyscore":"","newspost_id":null},"fixes":[{"source_id":96,"source_version_id":27,"major":"14","fixed_minor":3,"raw":{"id":96,"patch_id":29,"version_id":27,"fixed_minor":3},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
