All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access.
References
Configurations
No configuration.
History
21 Nov 2024, 09:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.enterprisedb.com/docs/epas/15/epas_rel_notes/ - | |
References | () https://www.enterprisedb.com/docs/epas/latest/epas_rel_notes/ - | |
References | () https://www.enterprisedb.com/docs/security/advisories/cve20244545/ - | |
Summary |
|
14 May 2024, 15:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 15:44
Updated : 2024-11-21 09:43
NVD link : CVE-2024-4545
Mitre link : CVE-2024-4545
CVE.ORG link : CVE-2024-4545
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management