Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability involves a PostgreSQL extension that manages partitioned tables. A flaw allows a user with specific database privileges to inject malicious SQL commands, potentially leading to full database compromise and operating system command execution. The main concern is confirming relevance and exposure due to the specialized access required.
- SQL injection in database management tool.
- Compromise risk if specific database access is granted.
- Confirm relevance and check database access controls.
Attack Path
How an attacker could exploit the issue
An attacker with INSERT and UPDATE privileges on the `partman_user` role can inject malicious SQL into the `part_config.time_encoder` field. When `pg_partman_bgw` later processes this configuration to create a new partition, it will execute the injected SQL with the privileges of the `pg_partman_bgw` role, which by default is a PostgreSQL superuser. This allows for widespread database compromise and execution of operating system commands.
- Requires authenticated database access.
- Inject SQL into configuration.
- Database and OS compromise.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a role with INSERT and UPDATE privileges on part_config can store arbitrary SQL within the `part_config.time_encoder` field. This stored SQL could then be executed with elevated privileges by the `pg_partman_bgw` process when creating child partitions, potentially leading to database-wide compromise.
- SQL injection in partition creation.
- Stored SQL executed with superuser privileges.
- Database compromise and OS command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The PostgreSQL extension pg_partman requires action from database administrators and potentially platform or infrastructure teams responsible for the PostgreSQL environment. The first step is to identify all PostgreSQL instances running pg_partman, determine their reachability and criticality, and confirm the accountable owner. Subsequently, a remediation plan can be developed based on the identified risks.
- Database administrators should own the issue.
- Verify pg_partman reachability and criticality.
- Plan for upgrades during maintenance windows.