Back

HIGH

postgresql: Command injection via "COPY TO/FROM PROGRAM" function

Published Apr 1, 2019

Description

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

Affected products

Remediation

Red Hat statement

The PostgreSQL Project does not consider this to be a vulnerability. By design, database super users have full rights to the context that PostgreSQL executes within, including reading & writing all files and code execution. See External References for more details. Red Hat Product Security concurs with upstream's assessment that this is not a vulnerability. Customers are advised to follow best practice when configuring PostgreSQL, which includes allocating only the minimum privileges to users. Super user privileges in particular must be very carefully controlled.

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Apr 1, 2019
Updated Nov 15, 2024
Reserved Feb 26, 2019

CISA Vulnrichment

Updated Apr 24, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Public date Mar 20, 2019
Bugzilla 1695982

ENISA EUVD

Assigner mitre
Published Apr 1, 2019
Updated Nov 15, 2024

GitHub

No data