« Volver al listado

CVE-2025-8715

Estado: AplazadaAlta (8.8)—

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inyección de metacomandos en nombres de objetos dentro de dumps de pg_dump que se ejecutan al restaurar en psql (cliente); requiere interacción del usuario (UI:R). El impacto principal es ejecución de comandos arbitrarios del SO, secundarios inyección SQL como superusuario y manipulación de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-8715",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8715",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-15T03:55:57.753539Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "PostgreSQL",
          "versions": [
            {
              "status": "affected",
              "version": "17",
              "lessThan": "17.6",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "16",
              "lessThan": "16.10",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "15",
              "lessThan": "15.14",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "14",
              "lessThan": "14.19",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "11.20",
              "lessThan": "13.22",
              "versionType": "rpm"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-14T13:15:37.880",
  "references": [
    {
      "url": "https://www.postgresql.org/support/security/CVE-2025-8715/",
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "description": [
        {
          "lang": "en",
          "value": "CWE-93"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name.  The same attacks can achieve SQL injection as a superuser of the restore target server.  pg_dumpall, pg_restore, and pg_upgrade are also affected.  Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.  Versions before 11.20 are unaffected.  CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it."
    },
    {
      "lang": "es",
      "value": "La neutralización incorrecta de saltos de línea en pg_dump en PostgreSQL permite a un usuario del servidor de origen inyectar código arbitrario para su ejecución en tiempo de restauración como la cuenta del sistema operativo cliente que ejecuta psql para restaurar el volcado, mediante metacomandos psql dentro de un nombre de objeto específicamente manipulado. Los mismos ataques pueden lograr la inyección SQL como superusuario del servidor de destino de la restauración. pg_dumpall, pg_restore y pg_upgrade también se ven afectados. Las versiones anteriores a PostgreSQL 17.6, 16.10, 15.14, 14.19 y 13.22 están afectadas. Las versiones anteriores a la 11.20 no se ven afectadas. CVE-2012-0868 había corregido este tipo de problema, pero la versión 11.20 lo reintrodujo."
    }
  ],
  "lastModified": "2026-06-17T10:07:29.680",
  "sourceIdentifier": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}