CVE-2023-31131

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-31131
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31131.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-31131
Withdrawn
2024-05-30T01:42:12.381896Z
Published
2023-05-15T22:15:12Z
Modified
2024-05-14T12:56:15.064287Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite data or system files potentially leading to crash or malfunction of the system. Any files which are accessible to the running process are at risk. All users are requested to upgrade to Greenplum Database version 6.23.2 or higher. There are no known workarounds for this vulnerability.

References

Affected packages

Git / github.com/greenplum-db/gpdb

Affected ranges

Type
GIT
Repo
https://github.com/greenplum-db/gpdb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

5.*

5.0.0-alpha.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-alpha.5
5.0.0-alpha.6
5.0.0-alpha.7
5.0.0-alpha.8
5.0.0-beta.1
5.0.0-beta.10
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-beta.7
5.0.0-beta.8
5.0.0-beta.9

6.*

6.0.0
6.0.0-alpha-1-releng
6.0.0-alpha.0
6.0.0-alpha.1
6.0.0-alpha.2
6.0.0-beta.1
6.0.0-beta.2
6.0.0-beta.3
6.0.0-beta.4
6.0.0-beta.6
6.0.0-beta.7
6.0.1
6.1.0
6.1.1
6.10.0
6.10.1
6.11.0
6.11.1
6.11.2
6.12.0
6.12.1
6.13.0
6.14.0
6.14.1
6.15.0
6.16.0
6.16.1
6.16.2
6.17.0
6.17.1
6.17.2
6.18.0
6.18.1
6.18.2
6.19.0
6.19.1
6.19.2
6.19.3
6.2.0
6.2.1
6.20.0
6.20.1
6.20.2
6.20.3
6.21.0
6.21.1
6.22.0
6.22.1
6.22.2
6.23.0
6.23.1
6.3.0
6.4.0
6.5.0
6.6.0
6.7.0
6.7.1
6.8.0
6.8.1
6.9.0
6.9.1

Other

Pre-5-disk-layout-change