Skip to main content
EPSS 0.7%top 48%

PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks (CVE-2024-4317)

0
Medium
Published: 05/24/2024 (05/24/2024, 07:31:18 UTC)
Source: GCVE Database
Product: postgresql

Description

PostgreSQL versions 14, 15, and 16 prior to 14.12, 15.7, and 16.3 respectively have a vulnerability in the built-in views pg_stats_ext and pg_stats_ext_exprs. These views lack proper authorization checks, allowing unprivileged database users to read statistical data, including most common values from CREATE STATISTICS commands of other users. This exposure may reveal sensitive column values or function results that the user should not access. The vulnerability affects existing installations unless they follow specific upgrade instructions. A patch is available to fix this issue.

Affected software

Affected versions
>=14.0.0 <14.12.0>=15.0.0 <15.7.0>=16.0.0 <16.3.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 15:16:16 UTC

Technical Analysis

The vulnerability CVE-2024-4317 in PostgreSQL involves missing authorization checks in the built-in views pg_stats_ext and pg_stats_ext_exprs. This flaw permits unprivileged database users to access statistical information, such as most common values derived from CREATE STATISTICS commands, belonging to other users. Such data exposure can leak sensitive column values or function results that would otherwise be inaccessible. The issue affects PostgreSQL major versions 14, 15, and 16 before the minor releases 14.12, 15.7, and 16.3 respectively. Installing an unaffected version only secures fresh PostgreSQL installations created after the update; existing installations remain vulnerable until they apply the vendor's remediation steps. The vulnerability is tracked under CVE-2024-4317 and is rated medium severity by Red Hat Product Security. A patch is available, and detailed remediation instructions are provided by Red Hat.

Potential Impact

Unprivileged database users can read statistical data from other users' CREATE STATISTICS commands via the vulnerable views. This may disclose sensitive column values or function results that the user is not authorized to access, potentially leading to information leakage within the database environment. The vulnerability does not allow direct modification or execution of arbitrary code but compromises data confidentiality.

Mitigation Recommendations

A patch is available for this vulnerability. Users should upgrade PostgreSQL to versions 14.12 or later, 15.7 or later, and 16.3 or later to remediate the issue. For existing PostgreSQL installations, simply installing the updated version is insufficient; administrators must follow the specific instructions in the PostgreSQL release notes and Red Hat advisory RHSA-2024:5927 to fully mitigate the vulnerability. Refer to https://access.redhat.com/articles/11258 for detailed update and remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:5927
Cve Count
2
Additional Cves
["CVE-2024-7348"]

Threat ID: 6a7573b7bf8831d539d93f13

Added to database: 08/07/2026, 05:57:11 UTC

Last enriched: 09/08/2026, 15:16:16 UTC

Last updated: 09/10/2026, 19:38:44 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses