- Description
- Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
- Source
- f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
Reproducing CVE-2024-10979: A Step-by-Step Guide https://t.co/zhz94B8K4m
@akaclandestine
23 Dec 2024
1218 Impressions
7 Retweets
19 Likes
8 Bookmarks
0 Replies
0 Quotes
Reproducing CVE-2024-10979: A Step-by-Step Guide #ReproduceCVE202410979 #StepByStepGuide #SAPSecurity #Vulnerability #EducationalPurposes https://t.co/uEYhCWLumf
@reverseame
22 Dec 2024
817 Impressions
2 Retweets
7 Likes
6 Bookmarks
0 Replies
0 Quotes
Postgresqlの脆弱性なんだ。へぇ~ CVE-2024-10979をローカルで再現してみる https://t.co/dCmmGhD0nB #Qiitaアドカレ #Qiita
@ricemountainer
16 Dec 2024
66 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10979をローカルで再現してみる https://t.co/uiKEUeBiIz #Qiitaアドカレ #Qiita
@yousukezan
16 Dec 2024
1767 Impressions
3 Retweets
24 Likes
6 Bookmarks
0 Replies
0 Quotes
CVE-2024-10979をローカルで再現してみる https://t.co/iTaMtSONya #Qiitaアドカレ #Qiita
@kk0128_
14 Dec 2024
97 Impressions
0 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2024-10979をローカルで再現してみる https://t.co/JCl3pVFEHS #Qiitaアドカレ #Qiita
@long10lang
14 Dec 2024
19 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10979 in PostgreSQL enables attackers to set arbitrary environment variables, potentially leading to arbitrary code execution. Ensure your PostgreSQL systems are updated to the latest patch to avoid vulnerabilities! https://t.co/CiMcVRF76G
@Shift6Security
3 Dec 2024
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
2024.11.20 セキュリティニュースアラート PostgreSQL PL/Perlに深刻な脆弱性 直ちに更新を(会員限定) - ITmedia エンタープライズ PostgreSQLに重大な脆弱性「CVE-2024-10979」があることが分かった。環境変数の制御不備による脆弱性で、これを悪用すると任意のコード実… https://t.co/KyMQ5Vtljg
@kawn2020
24 Nov 2024
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Nueva vulnerabilidad en PostgreSQL 🚨 El CVE-2024-10979 permite a atacantes sin privilegios la ejecución de código malicioso. 📉 💡 Actualiza ya a las versiones parcheadas. Detalles aquí: https://t.co/qJj98IcDKF #Ciberseguridad #PostgreSQL
@Cronsecure
21 Nov 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2024-10979
@transilienceai
21 Nov 2024
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Warning: Multiple vulnerabilities in in @PostgreSQL. #CVE-2024-10979 CVSS: 8.8 and others. Could potentially lead to full system compromise, so #Patch #Patch #Patch. More info: https://t.co/lPAaMwBUFw
@CCBalert
18 Nov 2024
157 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical PostgreSQL flaw (CVE-2024-10979) lets unprivileged users alter environment variables, potentially leading to code execution. Update to patched versions ASAP! #PostgreSQL #Cybersecurity #CVE202410979 https://t.co/hUG2cGRG3j
@TLDRStories
18 Nov 2024
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PostgreSQL Releases Security Update Addressing Multiple Vulnerabilities The vulnerabilities range in severity, with the most serious (CVE-2024-10979, CVSS 8.8) enabling arbitrary code execution in the context of the #PostgreSQL server #taryartar #LNXDB https://t.co/Z37Mg0L45v
@taryartar277196
18 Nov 2024
28 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
PostgreSQL Releases Security Update Addressing Multiple Vulnerabilities The vulnerabilities range in severity, with the most serious (CVE-2024-10979, CVSS 8.8) enabling arbitrary code execution in the context of the #PostgreSQL server https://t.co/xhcqxVcAnK
@the_yellow_fall
18 Nov 2024
130 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
2024年11月16日、PostgreSQLの開発チームは、オープンソースデータベースシステムPostgreSQLに重大なセキュリティ脆弱性が発見されたと発表した。この脆弱性は「CVE-2024-10979」として追跡され、CVSSスコアは8.8と高い深刻度。 #サイバーセキュリティ #PostgreSQL https://t.co/IdvSSk67yW
@innovaTopia_JP
18 Nov 2024
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PostgreSQL vulnerability - CVE-2024-10979 https://t.co/TKBaIr9nnT
@kayosoufiane
17 Nov 2024
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PostgreSQL: 4 CVEs fixed in 17.1, 16.5, 15.9, 14.14, 13.17, 12.21 https://t.co/ED0Y9JmSRA CVE-2024-10979 PostgreSQL PL/Perl environment variable changes execute arbitrary code, CVSS 8.8 CVE-2024-10978 PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID, CVSS 4.2
@oss_security
16 Nov 2024
411 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
PostgreSQL fixes CVE-2024-10979 #PostgreSQL #CVE-2024-10979 https://t.co/we62hkBBig
@pravin_karthik
16 Nov 2024
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PostgreSQLの最新バージョンで重大な脆弱性(CVE-2024-10979)が発見されました。この脆弱性により、特権のないユーザーが環境変数を不正に変更し、任意のコードを実行することが可能になります。迅速な対応が求められています。 #PostgreSQL #脆弱性 https://t.co/IdvSSk67yW
@innovaTopia_JP
16 Nov 2024
76 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: 8.8 Rated PostgreSQL Vulnerability Puts Databases at Risk - #CVE-2024-10979 CVE-2024-10979 Severity: 🔴 High Maturity: 🧨 Trending Learn more: https://t.co/wRDm41hV7G #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
16 Nov 2024
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical PostgreSQL Vulnerability Alert! CVE-2024-10979 (CVSS 8.8) allows unprivileged users to alter environment variables, leading to code execution or data leaks. Update now to patched versions: 17.1, 16.5, 15.9, 14.14, 13.17, 12.21. #CyberSecurity #PostgreSQL #Hacking #bug
@safeyourweb
16 Nov 2024
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PostgreSQLの深刻な脆弱性が修正された。CVE-2024-10979はCVSSスコア8.8で、非特権ユーザーが環境変数を書き換え可能のもの。PATHを書き換えることによる任意コード実行や(環境変数内の)価値ある情報窃取等の可能性。詳細はパッチ適用時間を稼ぐため非開示。 https://t.co/lEVBGjgn2G
@__kokumoto
15 Nov 2024
2046 Impressions
8 Retweets
34 Likes
8 Bookmarks
0 Replies
0 Quotes
🚨 Descubierta una vulnerabilidad de alta gravedad (CVE-2024-10979) en PostgreSQL, que permite a usuarios sin privilegios alterar las variables de entorno, lo que lleva a una posible ejecución de código o fugas de información https://t.co/bGIjGncyYS https://t.co/da4K6ClR3K
@elhackernet
15 Nov 2024
12942 Impressions
91 Retweets
255 Likes
55 Bookmarks
1 Reply
0 Quotes
Reproducing CVE-2024-10979: A Step-by-Step Guide https://t.co/R5Z3ChMTqO
@_r_netsec
15 Nov 2024
759 Impressions
5 Retweets
10 Likes
3 Bookmarks
0 Replies
0 Quotes
TheHackersNews: ⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/yPVaDBIxVq #Cybersecurity #Vu…
@jvquantum
15 Nov 2024
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/Wd53OAVf3f... https://t.co/x5hxVvzd6T
@IT_news_for_all
15 Nov 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/jZDOxjh1Pa #Cybersecurity #Vulnerability
@TheHackersNews
15 Nov 2024
12962 Impressions
43 Retweets
79 Likes
14 Bookmarks
1 Reply
5 Quotes
CVE-2024-10979 Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). … https://t.co/aJ36vo5Bzb
@CVEnew
14 Nov 2024
109 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "433D59A0-8811-4DDB-A9F7-D85C62F905CC",
"versionEndExcluding": "12.21",
"versionStartIncluding": "12.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "380F8048-FBE5-4606-93A3-915CFD229317",
"versionEndExcluding": "13.17",
"versionStartIncluding": "13.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FACF31C7-3B20-4BAE-A596-9C59D67406D8",
"versionEndExcluding": "14.14",
"versionStartIncluding": "14.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF12F1A2-3179-4DAC-B728-038B94954DC7",
"versionEndExcluding": "15.9",
"versionStartIncluding": "15.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "353CBD91-FC28-4DA3-B79A-F4F4DC80FA93",
"versionEndExcluding": "16.5",
"versionStartIncluding": "16.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCEB2049-EB8A-4703-B3FF-FC641623ED2C",
"versionEndExcluding": "17.1",
"versionStartIncluding": "17.0"
}
],
"operator": "OR"
}
]
}
]