PostgreSQL Privilege Escalation via Post-Operation Incomplete Privilege Checks
CVE-2022-1552 Published on August 31, 2022

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

Vendor Advisory NVD

Weakness Type

What is an Insufficient Cleanup Vulnerability?

The software does not properly "clean up" and remove temporary or supporting resources after they have been used.

CVE-2022-1552 has been classified to as an Insufficient Cleanup vulnerability or weakness.


Products Associated with CVE-2022-1552

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-1552 are published in PostgreSQL:

 

Exploit Probability

EPSS
3.04%
Percentile
86.42%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.