rpm package
opensuse/kubectl-cnpg&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/kubectl-cnpg&distro=openSUSE%20Tumbleweed
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-55769 | Cri | — | < 1.29.2-1.1 | 1.29.2-1.1 | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role hold | |
| CVE-2026-55765 | Hig | 8.5 | < 1.29.2-1.1 | 1.29.2-1.1 | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/uti | |
| CVE-2026-33816 | Cri | 9.8 | < 1.29.1-1.1 | 1.29.1-1.1 | Apr 7, 2026 | Memory-safety vulnerability in github.com/jackc/pgx/v5. | |
| CVE-2018-1058 | Hig | 8.8 | < 1.29.2-1.1 | 1.29.2-1.1 | Mar 2, 2018 | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected. |
- affected < 1.29.2-1.1fixed 1.29.2-1.1
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role hold
- affected < 1.29.2-1.1fixed 1.29.2-1.1
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/uti
- affected < 1.29.1-1.1fixed 1.29.1-1.1
Memory-safety vulnerability in github.com/jackc/pgx/v5.
- affected < 1.29.2-1.1fixed 1.29.2-1.1
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.