CVE-2020-14349: Opensuse Leap
High severity, CVSS 7.1. EPSS: 2.2% chance of exploitation in the next 30 days.
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
Affected products
- Opensuse Leap: version 15.1 only; version 15.2 only
- PostgreSQL PostgreSQL: from 10.0, before 10.14 (fixed in 10.14); from 11.0, before 11.9 (fixed in 11.9); from 12.0, before 12.4 (fixed in 12.4)
Published 2020-08-24. Last modified 2026-06-17.