CVE-2022-1552 - log back

CVE-2022-1552 edited at 16 May 2022 14:12:53
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Privilege escalation
Description
+ Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity.
References
Notes
CVE-2022-1552 created at 16 May 2022 14:09:17