Vulnerability Description
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 12.0, < 12.20 |
Related Weaknesses (CWE)
References
- https://www.postgresql.org/support/security/CVE-2024-7348/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/08/11/1
- https://security.netapp.com/advisory/ntap-20240822-0002/
FAQ
What is CVE-2024-7348?
CVE-2024-7348 is a vulnerability with a CVSS score of 8.8 (HIGH). Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The atta...
How severe is CVE-2024-7348?
CVE-2024-7348 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7348?
Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql.