CVE-2023-41115: Medium severity enterprisedb advanced server vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTLENCODE, an authenticated user can read any large object, regardless of that user's permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41115?
CVE-2023-41115 is considered a high-severity vulnerability due to the ability for authenticated users to access any large object regardless of permission settings.
How do I fix CVE-2023-41115?
To mitigate CVE-2023-41115, upgrade EnterpriseDB Postgres Advanced Server to the latest version as specified in the advisory.
Which versions of EnterpriseDB Postgres Advanced Server are affected by CVE-2023-41115?
CVE-2023-41115 affects versions prior to 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0.
Who can exploit CVE-2023-41115?
CVE-2023-41115 can be exploited by any authenticated user of the affected EnterpriseDB Postgres Advanced Server versions.
What is the nature of the vulnerability in CVE-2023-41115?
The vulnerability in CVE-2023-41115 allows unauthorized access to large objects through the UTL_ENCODE function, violating user permissions.