PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL (CVE-2024-0985)
Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.
AI Analysis
Technical Summary
CVE-2024-0985 is a vulnerability in PostgreSQL where a non-owner user executing the 'REFRESH MATERIALIZED VIEW CONCURRENTLY' command can run arbitrary SQL. This flaw is classified under CWE-271 (Improper Privilege Management). Red Hat has issued security advisories RHSA-2024:0950 and RHSA-2024:0988 providing updated PostgreSQL packages for Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7, respectively. The updates fix the vulnerability by restricting unauthorized SQL execution via this command. The PostgreSQL service is automatically restarted upon update installation to apply the fix.
Potential Impact
An attacker with non-owner database privileges could exploit this vulnerability to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. This elevates the risk of privilege escalation within the database environment. The severity is rated as high by Red Hat, reflecting the significant risk posed by unauthorized SQL execution.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2024-0985 for PostgreSQL packages in Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The PostgreSQL service will be automatically restarted after the update to ensure the fix is applied. No additional mitigation steps are required beyond applying the official patches.
PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL (CVE-2024-0985)
Description
Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-0985 is a vulnerability in PostgreSQL where a non-owner user executing the 'REFRESH MATERIALIZED VIEW CONCURRENTLY' command can run arbitrary SQL. This flaw is classified under CWE-271 (Improper Privilege Management). Red Hat has issued security advisories RHSA-2024:0950 and RHSA-2024:0988 providing updated PostgreSQL packages for Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7, respectively. The updates fix the vulnerability by restricting unauthorized SQL execution via this command. The PostgreSQL service is automatically restarted upon update installation to apply the fix.
Potential Impact
An attacker with non-owner database privileges could exploit this vulnerability to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. This elevates the risk of privilege escalation within the database environment. The severity is rated as high by Red Hat, reflecting the significant risk posed by unauthorized SQL execution.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2024-0985 for PostgreSQL packages in Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The PostgreSQL service will be automatically restarted after the update to ensure the fix is applied. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:1241
- Cve Count
- 1
Threat ID: 6a3da1fe4853345fc1836437
Added to database: 06/25/2026, 21:47:42 UTC
Last enriched: 08/12/2026, 17:43:16 UTC
Last updated: 09/10/2026, 19:24:53 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.