September 26, 2024: PostgreSQL 17 Released!

CVE-2020-14350

Uncontrolled search path element in CREATE EXTENSION

When a superuser runs certain CREATE EXTENSION statements, users may be able to execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are vulnerable.

In addition to correcting the extensions provided with PostgreSQL, the PostgreSQL Global Development Group is issuing guidance for third-party extension authors to secure their own work.

The PostgreSQL project thanks Andres Freund for reporting this problem.

Version Information

Affected Version Fixed In Fix Published
12 12.4 Aug. 13, 2020
11 11.9 Aug. 13, 2020
10 10.14 Aug. 13, 2020
9.6 9.6.19 Aug. 13, 2020
9.5 9.5.23 Aug. 13, 2020

For more information about PostgreSQL versioning, please visit the versioning page.

CVSS 3.0

Overall Score 7.1
Component core server
Vector AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Reporting Security Vulnerabilities

If you wish to report a new security vulnerability in PostgreSQL, please send an email to security@postgresql.org.

For reporting non-security bugs, please see the Report a Bug page.