CVE-2022-1552
PostgreSQL vulnerability analysis and mitigation

Overview

CVE-2022-1552 is a security vulnerability discovered in PostgreSQL affecting versions 10 through 14. The vulnerability was disclosed on May 12, 2022, and involves incomplete security restricted operation sandbox implementation in various PostgreSQL commands. The affected components include Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck functionalities (PostgreSQL News).

Technical details

The vulnerability stems from incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The affected commands either activated relevant protections too late or failed to activate them entirely. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a serious security risk (PostgreSQL Security).

Impact

When successfully exploited, this vulnerability allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity. This could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS) (NetApp Security).

Mitigation and workarounds

The primary mitigation is to update to PostgreSQL versions 14.3, 13.7, 12.11, 11.16, or 10.21, depending on the installed version. For users unable to update immediately, a temporary workaround involves disabling autovacuum, avoiding manual execution of the affected commands, and not restoring from pg_dump output. However, this workaround may lead to quick performance degradation. It's noted that VACUUM remains safe, and all commands are secure when a trusted user owns the target object (PostgreSQL News).

Additional resources


SourceThis report was generated using AI

Related PostgreSQL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8715HIGH8.8
  • PostgreSQLPostgreSQL
  • postgresql13-plperl
NoYesAug 14, 2025
CVE-2025-8714HIGH8.8
  • PostgreSQLPostgreSQL
  • postgresql17-plperl
NoYesAug 14, 2025
CVE-2025-12818MEDIUM5.9
  • PostgreSQLPostgreSQL
  • postgresql:13::postgresql
NoYesNov 13, 2025
CVE-2025-12817LOW3.1
  • PostgreSQLPostgreSQL
  • postgresql:13::postgresql-pltcl
NoYesNov 13, 2025
CVE-2025-8713LOW3.1
  • PostgreSQLPostgreSQL
  • postgresql15-plpython
NoYesAug 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management