Impact
The vulnerability is an SQL injection flaw in pg_partman’s inherit_template_properties() function. A partman_user who owns a template table can craft a column name that contains double‑quotes. When the background worker applies a primary key to a new child partition, the unescaped identifier is embedded into an ALTER TABLE ADD PRIMARY KEY statement. That statement is executed with the privileges of pg_partman_bgw.role, which by default is a PostgreSQL superuser. The flaw therefore allows a non‑superuser to gain superuser privileges inside the database and, because the background worker runs with server‑process privileges, to execute operating‑system commands as the PostgreSQL service account. This is an instance of CWE‑89. Affected systems The issue affects the pg_partman PostgreSQL extension, named pg_partman, in all releases prior to version 5.5.0. There are no further product version sub‑details in the CNA data, but the official advisory states that the fix is introduced in v5.5.0. Risk and exploitability The CVSS score is 8.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is based on a privilege escalation within the database: a partman_user must have the ability to create or modify a template table. Once a malicious column name is inserted, subsequent partition creation triggers the injection. Because the error occurs when the background worker fires, the exploit does not require network or remote access; it can be executed locally by any user with the necessary role. The resulting compromise spans the entire database and can lead to arbitrary operating‑system command execution. Mitigation and Remediation
Affected Systems
pg_partman (pgpartman:pg_partman), any PostgreSQL database using the extension with a version older than 5.5.0.
Risk and Exploitability
High severity CVSS 8.5; EPSS not available; not in KEV. The vulnerability can be exploited by a partman_user who owns a template table. The exploit escalates privileges to a superuser and permits OS command execution through the background worker. No external media is required.
OpenCVE Enrichment