CyberRota Analysis
AI-GeneratedThe pg_partman PostgreSQL extension is vulnerable due to improper handling of user input in the undo_partition() function, allowing a role with partman_user access to execute arbitrary SQL with the caller's privileges. This could lead to unauthorized access and manipulation of data, impacting confidentiality, integrity, and availability. Database administrators and organizations using versions prior to 5.5.0 should prioritize upgrading to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with partman_user access can store SQL rather than a function name, and the SQL executes with the privileges of the caller that invokes undo_partition(). The function is not part of the default background-worker path, which limits the automatic superuser escalation described by the related create-partition vulnerability, but a privileged caller can still have its available confidentiality, integrity, and availability permissions abused. This issue is fixed in version 5.5.0.