CVE-2023-41117: Critical severity enterprisedb advanced server vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against searchpath attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41117?
CVE-2023-41117 is rated as critical due to its potential to allow unauthorized access and execution of privileged functions.
How do I fix CVE-2023-41117?
To fix CVE-2023-41117, upgrade your EnterpriseDB Postgres Advanced Server to version 11.21.32, 12.16.20, 13.12.16, 14.9.0, or 15.4.0 or later.
What versions are affected by CVE-2023-41117?
CVE-2023-41117 affects EnterpriseDB Postgres Advanced Server versions prior to 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0.
What kind of vulnerability is CVE-2023-41117?
CVE-2023-41117 is a security vulnerability related to inadequate protections on functions that run with SECURITY DEFINER privileges.
Can CVE-2023-41117 lead to data breaches?
Yes, CVE-2023-41117 can potentially lead to data breaches by allowing unauthorized users to execute sensitive database operations.