Vulnerability Description
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription().
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2Ndquadrant | Pglogical | < 2.3.4 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1954112Issue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954112Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2021-3515?
CVE-2021-3515 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of...
How severe is CVE-2021-3515?
CVE-2021-3515 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3515?
Check the references section above for vendor advisories and patch information. Affected products include: 2Ndquadrant Pglogical.