CVE-2023-31043: High severity enterprisedb advanced server vulnerability
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edbfilterlog.redactpasswordcommands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31043?
CVE-2023-31043 has a medium severity rating due to potential exposure of sensitive password information in logs.
How do I fix CVE-2023-31043?
To fix CVE-2023-31043, upgrade to EnterpriseDB Postgres Advanced Server versions 10.23.33, 11.18.29, 12.13.17, 13.9.13, or 14.6.0 or later.
What are the consequences of CVE-2023-31043?
The consequences of CVE-2023-31043 include unauthorized access to unredacted passwords logged in certain user management commands.
Which versions of EnterpriseDB Postgres Advanced Server are affected by CVE-2023-31043?
Versions 10.23.32 and earlier, 11.18.28 and earlier, 12.13.16 and earlier, 13.9.12 and earlier, and 14.1.0 to 14.5.0 of EnterpriseDB Postgres Advanced Server are affected.
Is CVE-2023-31043 a remote exploitation vulnerability?
CVE-2023-31043 is not a remote exploitation vulnerability but rather a local logging issue that can expose sensitive information.