Vulnerabilities (CVE)

Filtered by vendor Aiven Subscribe
Filtered by product Aiven-db-migrate
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-55282 1 Aiven 1 Aiven-db-migrate 2025-08-21 N/A 9.1 CRITICAL
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside PostgreSQL databases during a migration from an untrusted source server. By exploiting a lack of search_path restriction, an attacker can override pg_catalog and execute untrusted operators as a superuser. This vulnerability is fixed in 1.0.7.
CVE-2025-55283 1 Aiven 1 Aiven-db-migrate 2025-08-21 N/A 9.1 CRITICAL
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases during a migration from an untrusted source server. The vulnerability stems from psql executing commands embedded in a dump from the source server. This vulnerability is fixed in 1.0.7.