PT-2025-33672 · Aiven · Aiven-Db-Migrate

Marinus Pfund

·

Published

2025-08-18

·

Updated

2025-08-23

·

CVE-2025-55282

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: aiven-db-migrate versions prior to 1.0.7
Description: aiven-db-migrate is a database migration tool. A privilege escalation issue exists that allows a user to elevate to superuser inside PostgreSQL databases during a migration from an untrusted source server. This is due to a lack of search path restriction, which allows an attacker to override pg catalog and execute untrusted operators as a superuser.
Recommendations: Update to aiven-db-migrate version 1.0.7 or later.

Exploit

Fix

LPE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-55282
GHSA-HMVF-93R4-36F9

Affected Products

Aiven-Db-Migrate