Description
PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.
Remediation
References
Related Vulnerabilities
Liferay DXP Excessive Iteration Vulnerability (CVE-2024-25144)
Jenkins CVE-2023-43498 Vulnerability (CVE-2023-43498)
PHP Improper Input Validation Vulnerability (CVE-2012-1172)
Jboss EAP Improper Authentication Vulnerability (CVE-2020-14299)
WordPress Plugin Convert Docx2post Arbitrary File Upload (1.4)