RHSA-2024:0992: Important: rh-postgresql10-postgresql security update
Important: rh-postgresql10-postgresql security update
Other sources
PostgreSQL is an advanced object-relational database management system (DBMS).<br>Security Fix(es):<br><li> postgresql: non-owner 'REFRESH MATERIALIZED VIEW CONCURRENTLY' executes arbitrary SQL (CVE-2024-0985)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0992?
The severity of RHSA-2024:0992 is classified as important.
How do I fix RHSA-2024:0992?
You can fix RHSA-2024:0992 by updating the affected rh-postgresql10-postgresql package to version 10.23-3.el7 or later.
What vulnerabilities are addressed in RHSA-2024:0992?
RHSA-2024:0992 addresses the vulnerability CVE-2024-0985 related to non-owner 'REFRESH MATERIALIZED VIEW CONCURRENTLY' executing arbitrary SQL.
Which software packages are affected by RHSA-2024:0992?
The affected packages in RHSA-2024:0992 include rh-postgresql10-postgresql, rh-postgresql10-postgresql-contrib, and other related packages up to version 10.23-3.el7.
What is CVE-2024-0985 in relation to RHSA-2024:0992?
CVE-2024-0985 is a vulnerability fixed in RHSA-2024:0992, which allows non-owners to execute arbitrary SQL using 'REFRESH MATERIALIZED VIEW CONCURRENTLY'.