Impact
The pg_partman extension can treat the part_config.time_encoder field as plain text and concatenate it into a SELECT statement without proper quoting. A role that has partman_user privileges can store malicious SQL as the time_encoder value, which then executes with the privileges of whoever calls undo_partition(). This flaw permits unauthenticated SQL injection that may read, modify, or delete data within the database, leading to significant confidentiality, integrity, and availability impacts.
Affected Systems
The vulnerability exists in the pg_partman PostgreSQL extension for all versions preceding 5.5.0. Users of any PostgreSQL deployment that have installed pg_partman and granted partman_user access to roles that might invoke undo_partition() are affected. The fixed version is 5.5.0 and later.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity of the flaw. No EPSS score is currently available, but the lack of listing in CISA KEV does not diminish the risk; attackers can exploit the vulnerability by crafting a malicious time_encoder value and executing undo_partition(). The exploitation requires database-level access and the presence of the vulnerable extension, but once achieved, it grants the attacker the privileges of the executing role.
OpenCVE Enrichment