Aiven aiven-db-migrate Privilege Escalation Vulnerability in PostgreSQL Databases

Vulnerability

A privilege escalation vulnerability has been identified in the Aiven database migration tool, aiven-db-migrate, prior to version 1.0.7. This vulnerability allows unauthorized elevation to superuser status within PostgreSQL databases during migrations from untrusted source servers. The issue arises because psql executes commands embedded in the database dump from the source server, potentially leading to unauthorized access or modifications.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation to superuser level in PostgreSQL databases, which could lead to unrestricted access and control over the database, including the ability to execute arbitrary commands or modify critical data.

Reproduction

To reproduce this vulnerability, use aiven-db-migrate version prior to 1.0.7 to migrate a PostgreSQL database from an untrusted source server. During the migration process, the psql tool will execute commands embedded in the database dump from the source server, leading to unauthorized privilege escalation.

Remediation

Users are advised to upgrade to aiven-db-migrate version 1.0.7 or later. If migrating from untrusted sources, ensure to use the latest version of the tool.

Added: Aug 18, 2025, 5:20 PM
Updated: Aug 18, 2025, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.8
remediation
7.7
relevance
0.4
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.