Medium severity6.7NVD Advisory· Published Jun 1, 2021· Updated Jun 17, 2026
CVE-2021-3515
CVE-2021-3515
Description
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- pglogical/pglogicaldescription
Patches
Vulnerability mechanics
References
1- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.