CVE-2023-41119: High severity EnterpriseDB Advanced Server vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function dbmsaqmovetoexceptionqueue that may be used to elevate a user's privileges to superuser. This function accepts the OID of a table, and then accesses that table as the superuser by using SELECT and DML commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41119?
CVE-2023-41119 is classified as a critical vulnerability due to its potential to allow privilege escalation to superuser.
How do I fix CVE-2023-41119?
To address CVE-2023-41119, upgrade your EnterpriseDB Postgres Advanced Server to versions 11.21.32, 12.16.20, 13.12.16, 14.9.0, or 15.4.0 and apply any relevant security patches.
Which versions of EnterpriseDB are affected by CVE-2023-41119?
CVE-2023-41119 impacts EnterpriseDB Postgres Advanced Server versions prior to 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0.
What is the attack vector for CVE-2023-41119?
The attack vector for CVE-2023-41119 primarily involves the misuse of the _dbms_aq_move_to_exception_queue function to escalate privileges.
Is there a workaround for CVE-2023-41119?
Currently, there are no specific workarounds for CVE-2023-41119 other than applying the recommended updates to mitigate the vulnerability.