PT-2025-14903 · Aiven · Aiven-Extras

Published

2025-04-04

·

Updated

2025-04-05

·

CVE-2025-31480

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aiven-extras versions prior to 1.1.16
Description This issue is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases using the aiven-extras package. It leverages the format function not being schema-prefixed.
Recommendations For versions prior to 1.1.16, install version 1.1.16 and run the command ALTER EXTENSION aiven extras UPDATE TO '1.1.16' in each database where aiven extras has been installed.

Exploit

Fix

LPE

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2025-31480
GHSA-33XH-JQGF-6627

Affected Products

Aiven-Extras