CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local Unix socket, then demotes the session with SET ROLE pg_monitor. SET ROLE changes only current_user; session_user remains postgres. Any SQL expression evaluated inside the scrape session can invoke RESET ROLE to recover real superuser privileges, then use COPY ... TO PROGRAM to spawn an OS-level subprocess as the postgres user inside the primary pod. The READ ONLY transaction flag does not block this; it gates writes to database state, not external processes. This vulnerability is fixed in 1.29.1 and 1.28.3.
The CloudNativePG metrics exporter establishes a connection to PostgreSQL as the 'postgres' superuser via the pod's local socket, then reduces session privileges using the SET ROLE pg_monitor command. However, SET ROLE only changes current_user — session_user remains 'postgres'. Any SQL expression executed within the scraping session can invoke RESET ROLE, restoring full superuser privileges, after which the COPY ... TO PROGRAM command allows running any subprocess of the operating system as the 'postgres' user on the main pod. The READ ONLY transaction mechanism does not block this attack, as it only protects against writing to database state, not against running external processes.
An attacker can execute arbitrary system commands (OS-level command execution) as the 'postgres' user inside a Kubernetes pod, which may lead to database control compromise, violation of data confidentiality and integrity, and further lateral movement within the cluster environment.
CloudNativePG should be updated to version 1.29.1 or 1.28.3, in which the vulnerability has been fixed. Patching is available in the official project repository.
CloudNativePG in versions earlier than 1.29.1 and 1.28.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLinuxfoundation Cloudnativepg
APPLinuxfoundation< 1.28.31.29.0 – 1.29.1 (excl.)
Related vulnerabilities
containerd CRI plugin: brak walidacji etykiet obrazu umożliwia RCE na hoście
AGL app-framework-main: Zip Slip + TOCTOU umożliwiają zapis dowolnych plików
Spinnaker Echo: nieograniczony dostęp SPeL umożliwia RCE
RCE w Spinnaker — wykonanie dowolnych poleceń na podach clouddriver
RCE w Kedro przez niezabezpieczoną konfigurację logowania (dictConfig)