---
cve: "CVE-2017-16082"
severity: "LOW"
cvss: 3.1
epss: "10.5%"
vendor: "HackerOne"
kev: false
exploited: false
published: "2018-06-07 02:29:01"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T21:51:25+02:00"
---

# CVE-2017-16082

> 3.1 LOW

## Beschreibung

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

## Referenzen

- <https://node-postgres.com/announcements#2017-08-12-code-execution-vulnerability>
- <https://nodesecurity.io/advisories/521>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-16082) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
