CVE-2024-10979

Published Nov 14, 2024

Last updated 15 days ago

Overview

Description
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Source
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
CWE-15
nvd@nist.gov
CWE-610

Social media

Hype score
Not currently trending
  1. Reproducing CVE-2024-10979: A Step-by-Step Guide https://t.co/zhz94B8K4m

    @akaclandestine

    23 Dec 2024

    1218 Impressions

    7 Retweets

    19 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  2. Reproducing CVE-2024-10979: A Step-by-Step Guide #ReproduceCVE202410979 #StepByStepGuide #SAPSecurity #Vulnerability #EducationalPurposes https://t.co/uEYhCWLumf

    @reverseame

    22 Dec 2024

    817 Impressions

    2 Retweets

    7 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  3. Postgresqlの脆弱性なんだ。へぇ~ CVE-2024-10979をローカルで再現してみる https://t.co/dCmmGhD0nB #Qiitaアドカレ #Qiita

    @ricemountainer

    16 Dec 2024

    66 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-10979をローカルで再現してみる https://t.co/uiKEUeBiIz #Qiitaアドカレ #Qiita

    @yousukezan

    16 Dec 2024

    1767 Impressions

    3 Retweets

    24 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10979をローカルで再現してみる https://t.co/iTaMtSONya #Qiitaアドカレ #Qiita

    @kk0128_

    14 Dec 2024

    97 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. CVE-2024-10979をローカルで再現してみる https://t.co/JCl3pVFEHS #Qiitaアドカレ #Qiita

    @long10lang

    14 Dec 2024

    19 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-10979 in PostgreSQL enables attackers to set arbitrary environment variables, potentially leading to arbitrary code execution. Ensure your PostgreSQL systems are updated to the latest patch to avoid vulnerabilities! https://t.co/CiMcVRF76G

    @Shift6Security

    3 Dec 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 2024.11.20 セキュリティニュースアラート PostgreSQL PL/Perlに深刻な脆弱性 直ちに更新を(会員限定) - ITmedia エンタープライズ PostgreSQLに重大な脆弱性「CVE-2024-10979」があることが分かった。環境変数の制御不備による脆弱性で、これを悪用すると任意のコード実… https://t.co/KyMQ5Vtljg

    @kawn2020

    24 Nov 2024

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Nueva vulnerabilidad en PostgreSQL 🚨 El CVE-2024-10979 permite a atacantes sin privilegios la ejecución de código malicioso. 📉 💡 Actualiza ya a las versiones parcheadas. Detalles aquí: https://t.co/qJj98IcDKF #Ciberseguridad #PostgreSQL

    @Cronsecure

    21 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Actively exploited CVE : CVE-2024-10979

    @transilienceai

    21 Nov 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Warning: Multiple vulnerabilities in in @PostgreSQL. #CVE-2024-10979 CVSS: 8.8 and others. Could potentially lead to full system compromise, so #Patch #Patch #Patch. More info: https://t.co/lPAaMwBUFw

    @CCBalert

    18 Nov 2024

    157 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Critical PostgreSQL flaw (CVE-2024-10979) lets unprivileged users alter environment variables, potentially leading to code execution. Update to patched versions ASAP! #PostgreSQL #Cybersecurity #CVE202410979 https://t.co/hUG2cGRG3j

    @TLDRStories

    18 Nov 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. PostgreSQL Releases Security Update Addressing Multiple Vulnerabilities The vulnerabilities range in severity, with the most serious (CVE-2024-10979, CVSS 8.8) enabling arbitrary code execution in the context of the #PostgreSQL server #taryartar #LNXDB https://t.co/Z37Mg0L45v

    @taryartar277196

    18 Nov 2024

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. PostgreSQL Releases Security Update Addressing Multiple Vulnerabilities The vulnerabilities range in severity, with the most serious (CVE-2024-10979, CVSS 8.8) enabling arbitrary code execution in the context of the #PostgreSQL server https://t.co/xhcqxVcAnK

    @the_yellow_fall

    18 Nov 2024

    130 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 2024年11月16日、PostgreSQLの開発チームは、オープンソースデータベースシステムPostgreSQLに重大なセキュリティ脆弱性が発見されたと発表した。この脆弱性は「CVE-2024-10979」として追跡され、CVSSスコアは8.8と高い深刻度。 #サイバーセキュリティ #PostgreSQL https://t.co/IdvSSk67yW

    @innovaTopia_JP

    18 Nov 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. PostgreSQL vulnerability - CVE-2024-10979 https://t.co/TKBaIr9nnT

    @kayosoufiane

    17 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. PostgreSQL: 4 CVEs fixed in 17.1, 16.5, 15.9, 14.14, 13.17, 12.21 https://t.co/ED0Y9JmSRA CVE-2024-10979 PostgreSQL PL/Perl environment variable changes execute arbitrary code, CVSS 8.8 CVE-2024-10978 PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID, CVSS 4.2

    @oss_security

    16 Nov 2024

    411 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. PostgreSQL fixes CVE-2024-10979 #PostgreSQL #CVE-2024-10979 https://t.co/we62hkBBig

    @pravin_karthik

    16 Nov 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. PostgreSQLの最新バージョンで重大な脆弱性(CVE-2024-10979)が発見されました。この脆弱性により、特権のないユーザーが環境変数を不正に変更し、任意のコードを実行することが可能になります。迅速な対応が求められています。 #PostgreSQL #脆弱性 https://t.co/IdvSSk67yW

    @innovaTopia_JP

    16 Nov 2024

    76 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Threat Alert: 8.8 Rated PostgreSQL Vulnerability Puts Databases at Risk - #CVE-2024-10979 CVE-2024-10979 Severity: 🔴 High Maturity: 🧨 Trending Learn more: https://t.co/wRDm41hV7G #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    16 Nov 2024

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Critical PostgreSQL Vulnerability Alert! CVE-2024-10979 (CVSS 8.8) allows unprivileged users to alter environment variables, leading to code execution or data leaks. Update now to patched versions: 17.1, 16.5, 15.9, 14.14, 13.17, 12.21. #CyberSecurity #PostgreSQL #Hacking #bug

    @safeyourweb

    16 Nov 2024

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. PostgreSQLの深刻な脆弱性が修正された。CVE-2024-10979はCVSSスコア8.8で、非特権ユーザーが環境変数を書き換え可能のもの。PATHを書き換えることによる任意コード実行や(環境変数内の)価値ある情報窃取等の可能性。詳細はパッチ適用時間を稼ぐため非開示。 https://t.co/lEVBGjgn2G

    @__kokumoto

    15 Nov 2024

    2046 Impressions

    8 Retweets

    34 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 Descubierta una vulnerabilidad de alta gravedad (CVE-2024-10979) en PostgreSQL, que permite a usuarios sin privilegios alterar las variables de entorno, lo que lleva a una posible ejecución de código o fugas de información https://t.co/bGIjGncyYS https://t.co/da4K6ClR3K

    @elhackernet

    15 Nov 2024

    12942 Impressions

    91 Retweets

    255 Likes

    55 Bookmarks

    1 Reply

    0 Quotes

  24. Reproducing CVE-2024-10979: A Step-by-Step Guide https://t.co/R5Z3ChMTqO

    @_r_netsec

    15 Nov 2024

    759 Impressions

    5 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  25. TheHackersNews: ⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/yPVaDBIxVq #Cybersecurity #Vu…

    @jvquantum

    15 Nov 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. ⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/Wd53OAVf3f... https://t.co/x5hxVvzd6T

    @IT_news_for_all

    15 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. ⚠️ Researchers have identified a high-severity #vulnerability (CVE-2024-10979) in PostgreSQL, allowing unprivileged users to alter environment variables, leading to potential code execution or information leaks. Read: https://t.co/jZDOxjh1Pa #Cybersecurity #Vulnerability

    @TheHackersNews

    15 Nov 2024

    12962 Impressions

    43 Retweets

    79 Likes

    14 Bookmarks

    1 Reply

    5 Quotes

  28. CVE-2024-10979 Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). … https://t.co/aJ36vo5Bzb

    @CVEnew

    14 Nov 2024

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations