CVE-2023-41116: Medium severity EnterpriseDB Advanced Server vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless of that user's permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41116?
CVE-2023-41116 has a moderate severity, as it allows unauthorized access to refresh materialized views in EPAS.
How do I fix CVE-2023-41116?
To fix CVE-2023-41116, update your EnterpriseDB Postgres Advanced Server to version 11.21.32 or later, or to version 12.16.20, 13.12.16, 14.9.0, or 15.4.0.
Who is affected by CVE-2023-41116?
CVE-2023-41116 affects all versions of EnterpriseDB Postgres Advanced Server prior to the specified patches mentioned in the vulnerability details.
What type of vulnerability is CVE-2023-41116?
CVE-2023-41116 is an authorization vulnerability that allows authenticated users to perform operations beyond their permissions.
Can the exploitation of CVE-2023-41116 lead to data integrity issues?
Yes, the exploitation of CVE-2023-41116 can potentially lead to data integrity issues by allowing unauthorized users to refresh materialized views.