{"id":"CVE-2021-3515","details":"A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription().","modified":"2026-07-08T05:57:20.416354385Z","published":"2021-06-01T14:15:10.337Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"2ndquadrant:pglogical","cpes":["cpe:2.3:a:2ndquadrant:pglogical:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.6.26"}]}]},"references":[{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1954112"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/2ndquadrant/pglogical","events":[{"introduced":"0"},{"fixed":"086651fcb97de643b02befa838c426c632021f03"}],"database_specific":{"cpe":"cpe:2.3:a:2ndquadrant:pglogical:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.4"}],"source":"CPE_RANGE"}}],"versions":["REL2_3_3","REL2_3_2","REL2_3_1","REL2_3_0","REL2_2_2","REL2_2_1","REL2_2_0","REL2_1_1","REL2_1_0","REL2_0_1","REL2_0_0","REL1_2_0","pglogical/REL1_1_0","REL1_1_0","REL1_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3515.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}