CVE-2025-55283

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases during a migration from an untrusted source server. The vulnerability stems from psql executing commands embedded in a dump from the source server. This vulnerability is fixed in 1.0.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aiven:aiven-db-migrate:*:*:*:*:*:*:*:*

History

21 Aug 2025, 21:38

Type Values Removed Values Added
References () https://github.com/aiven/aiven-db-migrate/commit/36f6c7f7d06216975f625da0a1cb514253c4b3df - () https://github.com/aiven/aiven-db-migrate/commit/36f6c7f7d06216975f625da0a1cb514253c4b3df - Patch
References () https://github.com/aiven/aiven-db-migrate/security/advisories/GHSA-wqhc-grmj-fjvg - () https://github.com/aiven/aiven-db-migrate/security/advisories/GHSA-wqhc-grmj-fjvg - Vendor Advisory
CPE cpe:2.3:a:aiven:aiven-db-migrate:*:*:*:*:*:*:*:*
First Time Aiven
Aiven aiven-db-migrate
Summary
  • (es) aiven-db-migrate es una herramienta de migración de bases de datos de Aiven. Antes de la versión 1.0.7, existía una vulnerabilidad de escalada de privilegios que permitía la elevación a superusuario dentro de bases de datos PostgreSQL durante una migración desde un servidor de origen no confiable. La vulnerabilidad se origina cuando psql ejecuta comandos incrustados en un volcado del servidor de origen. Esta vulnerabilidad se corrigió en la versión 1.0.7.

18 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-18 17:15

Updated : 2025-08-21 21:38


NVD link : CVE-2025-55283

Mitre link : CVE-2025-55283

CVE.ORG link : CVE-2025-55283


JSON object : View

Products Affected

aiven

  • aiven-db-migrate
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')