Skip to main content
EPSS 1.8%top 23%

PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL (CVE-2024-0985)

0
High
Published: 03/06/2024 (03/06/2024, 11:02:19 UTC)
Source: GCVE Database
Product: postgresql

Description

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.

Affected software

redhat/postgresql
pkg:rpm/redhat/postgresql
Affected versions
>=9.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 17:43:16 UTC

Technical Analysis

CVE-2024-0985 is a vulnerability in PostgreSQL where a non-owner user executing the 'REFRESH MATERIALIZED VIEW CONCURRENTLY' command can run arbitrary SQL. This flaw is classified under CWE-271 (Improper Privilege Management). Red Hat has issued security advisories RHSA-2024:0950 and RHSA-2024:0988 providing updated PostgreSQL packages for Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7, respectively. The updates fix the vulnerability by restricting unauthorized SQL execution via this command. The PostgreSQL service is automatically restarted upon update installation to apply the fix.

Potential Impact

An attacker with non-owner database privileges could exploit this vulnerability to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification. This elevates the risk of privilege escalation within the database environment. The severity is rated as high by Red Hat, reflecting the significant risk posed by unauthorized SQL execution.

Mitigation Recommendations

Red Hat has released official security updates addressing CVE-2024-0985 for PostgreSQL packages in Red Hat Enterprise Linux 9 and Red Hat Software Collections for RHEL 7. Users should apply these updates promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. The PostgreSQL service will be automatically restarted after the update to ensure the fix is applied. No additional mitigation steps are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:1241
Cve Count
1

Threat ID: 6a3da1fe4853345fc1836437

Added to database: 06/25/2026, 21:47:42 UTC

Last enriched: 08/12/2026, 17:43:16 UTC

Last updated: 09/10/2026, 19:24:53 UTC

Views: 52

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses