AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-14350

HIGH · CVSS 7.3 EPSS 0.53%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-08-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-14350
Severity
HIGH
CVSS
7.3
EPSS
0.53%

Original NVD Description

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.