PT-2023-19938 · Timescale+1 · Timescaledb+1

Thanasi

·

Published

2023-02-14

·

Updated

2025-03-04

·

CVE-2023-25149

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TimescaleDB versions 2.8.0 through 2.9.2
Description TimescaleDB has a privilege escalation issue due to the telemetry job running with an unlocked search path, allowing malicious users to create functions that would be executed by the telemetry job. To exploit this, a user needs to be able to create objects in a database and then get a superuser to install TimescaleDB into their database. When installed as a trusted extension, non-superusers can install it without help from a superuser. The issue is not exploitable on instances in Timescale Cloud and Managed Service for TimescaleDB due to additional security provisions.
Recommendations For versions 2.8.0 through 2.9.2, update to version 2.9.3 to fix the issue. As a mitigation, lock down the search path of the user running the telemetry job to not include schemas writable by other users.

Exploit

Fix

Improper Privilege Management

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3660
BIT-TIMESCALEDB-2023-25149
CVE-2023-25149
GHSA-44JH-J22R-33WQ

Affected Products

Alt Linux
Timescaledb