CVE-2022-26520

CRITICALCVSS 9.8/10EPSS 2.93%

Last modified

CVE-2022-26520 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. EPSS estimates a 2.93% chance of exploitation in the next 30 days.

Description

In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.93%

85.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PostgresqlPostgresql Jdbc Driver>= 42.1.0, <= 42.1.4
PostgresqlPostgresql Jdbc Driver>= 42.3.0, < 42.3.3
DebianDebian Linux10.0
DebianDebian Linux11.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-26520?
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties
How severe is CVE-2022-26520?
CVE-2022-26520 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.93% probability of exploitation in the next 30 days.
How do I fix CVE-2022-26520?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-26520?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST