RHSA-2024:0988: Important: rh-postgresql13-postgresql security update
Important: rh-postgresql13-postgresql security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS). <br>Security Fix(es):<br><li> postgresql: non-owner 'REFRESH MATERIALIZED VIEW CONCURRENTLY' executes arbitrary SQL (CVE-2024-0985)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the security issues addressed in RHSA-2024:0988?
RHSA-2024:0988 addresses a vulnerability where non-owners can execute arbitrary SQL using 'REFRESH MATERIALIZED VIEW CONCURRENTLY' (CVE-2024-0985).
What is the severity level of RHSA-2024:0988?
The severity level of RHSA-2024:0988 is classified as important.
How can I fix RHSA-2024:0988?
To fix RHSA-2024:0988, you should update to PostgreSQL version 13.14-1.el7 or later.
Which software packages are affected by RHSA-2024:0988?
The affected software packages include rh-postgresql13-postgresql, rh-postgresql13-postgresql-contrib, and several others under Red Hat Software Collections.
When should I apply the updates for RHSA-2024:0988?
It is recommended to apply the updates for RHSA-2024:0988 as soon as possible to mitigate the security risks.