« Volver al listado

CVE-2017-16082

Estado: ModificadaCrítica (9.8)—💥 PoC

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-16082",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "HackerOne",
          "product": "pg node module",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.11.2 || >= 3.0.0 < 3.6.4 || >= 4.0.0 < 4.5.7 || >= 5.0.0 < 5.2.1 || >= 6.0.0 < 6.0.5 || >= 6.1.0 < 6.1.6 || >= 6.2.0 < 6.2.5 || >= 6.3.0 < 6.3.3 || >= 6.4.0 < 6.4.2 || >= 7.0.0 < 7.0.2 || >= 7.1.0 < 7.1.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-06-07T02:29:01.393",
  "references": [
    {
      "url": "https://node-postgres.com/announcements#2017-08-12-code-execution-vulnerability",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://nodesecurity.io/advisories/521",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://node-postgres.com/announcements#2017-08-12-code-execution-vulnerability",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://nodesecurity.io/advisories/521",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious."
    },
    {
      "lang": "es",
      "value": "Se ha encontrado una vulnerabilidad de ejecución remota de código en el módulo pg cuando la base de datos o consulta remotas especifican un nombre de columna especialmente manipulado. Hay dos escenarios en los que se podría ser vulnerable. 1) La ejecución de SQL inseguro proporcionado por el usuario, el cual contiene un nombre de columna malicioso. 2) La conexión a una base de datos insegura y la ejecución de una consulta que devuelve resultados en los que alguno de los nombres de columna es malicioso."
    }
  ],
  "lastModified": "2026-06-17T01:08:46.077",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2E86DE6-91B1-40C9-A2E9-B48D8516233F",
              "versionEndExcluding": "2.11.2",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A7F10EE-D2CE-418B-BE57-2C377964D7F5",
              "versionEndExcluding": "3.6.4",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "629AB425-6D93-4F01-9F92-84F43811EF67",
              "versionEndExcluding": "4.5.7",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08F10CAA-2246-4988-A15E-B2C3DDB0C1F1",
              "versionEndExcluding": "5.2.1",
              "versionStartExcluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D8D3D99-E330-4AA1-89F9-321A4346C7A8",
              "versionEndExcluding": "6.4.2",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:node-postgres:pg:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "548A5428-2541-420D-AFB7-3E92A103655A",
              "versionEndExcluding": "7.1.2",
              "versionStartIncluding": "7.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}