{"id":"CVE-2018-1115","title":"postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile","summary":"postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able t…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-732","CWE-732"],"vendor":"postgresql","product":"postgresql","affected":["postgresql < 9.6.9","postgresql >= 10.0, < 10.4","leap = 15.1"],"patched":["postgresql 10.4"],"published":"2018-05-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:46.053","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-1115","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html","label":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/104285","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2018:2565","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2018:2566","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115","label":"secalert@redhat.com"},{"url":"https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/201810-08","label":"secalert@redhat.com"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/104285","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2018:2565","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2018:2566","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/201810-08","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.03898,"epssPercentile":0.89991,"ingestedAt":"2026-10-08T23:16:47.288Z","slug":"CVE-2018-1115","body":"## Overview\n\npostgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.\n\n## Affected\n\n- `postgresql < 9.6.9`\n- `postgresql >= 10.0, < 10.4`\n- `leap = 15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `postgresql 10.4`","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":50.1,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}