« Volver al listado

Pgxn

Pgxn PG Partman: vulnerabilidades y CVE

Pgxn PG Partman tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses6
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-61822Media (6.5)0.53%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one…
CVE-2026-61820Alta (8.5)0.73%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes…
CVE-2026-61819Alta (8.5)0.73%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place…
CVE-2026-61818Alta (8.5)0.51%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting…
CVE-2026-61817Alta (8.5)0.73%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate…
CVE-2026-61781Crítica (9.9)0.80%—18 sept 2026
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier…
CVE-2021-33204Crítica (9.8)2.2%—19 may 2021
In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1059.007 JavaScript4
  3. T1068 Exploitation for Privilege Escalation1
  4. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.