CVE-2023-41114: Medium severity EnterpriseDB Advanced Server vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions geturlastext and geturlasbytea that are publicly executable, thus permitting an authenticated user to read any file from the local filesystem or remote system regardless of that user's permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41114?
CVE-2023-41114 is classified as a significant vulnerability due to its potential to allow unauthorized access to database functions.
Which versions are affected by CVE-2023-41114?
CVE-2023-41114 affects EnterpriseDB Postgres Advanced Server versions prior to 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0.
How do I fix CVE-2023-41114?
To mitigate CVE-2023-41114, users should upgrade their EnterpriseDB Postgres Advanced Server to the latest available version.
What types of functions are exploited in CVE-2023-41114?
CVE-2023-41114 exploits the publicly executable functions get_url_as_text and get_url_as_bytea.
Can CVE-2023-41114 lead to data exposure?
Yes, CVE-2023-41114 can lead to potential data exposure due to unauthorized execution of certain database functions.