Skip to main content

Threats Tagged 'cve-2024-4317'

View all threats tagged with 'cve-2024-4317'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-4317

Threats Tagged 'cve-2024-4317'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat has issued a security advisory for PostgreSQL 15 addressing two vulnerabilities: CVE-2024-4317, where pg_stats_ext and pg_stats_ext_exprs lack proper authorization checks, and CVE-2024-7348, where relation replacement during pg_dump can execute arbitrary SQL. These issues could allow unauthorized actions within the database system. The update is rated as Important by Red Hat and applies to Red Hat Enterprise Linux 8.8 Extended Update Support. Users should apply the provided security update to mitigate these vulnerabilities.

Join the discussion

Red Hat has issued a security update for PostgreSQL 15 addressing two vulnerabilities: CVE-2024-7348, which allows arbitrary SQL execution during relation replacement in pg_dump, and CVE-2024-4317, which involves missing authorization checks in pg_stats_ext and pg_stats_ext_exprs. These issues could lead to unauthorized actions within the database system. The update is rated as important by Red Hat and applies to Red Hat Enterprise Linux 9 and its variants. Users are advised to apply the update following Red Hat's guidance.

Join the discussion

Red Hat has issued a security advisory for PostgreSQL 15 addressing two vulnerabilities: CVE-2024-7348, where relation replacement during pg_dump can execute arbitrary SQL, and CVE-2024-4317, where pg_stats_ext and pg_stats_ext_exprs lack proper authorization checks. These issues could allow unauthorized SQL execution and bypass of authorization controls. The advisory rates the update as important and provides updated packages for Red Hat Enterprise Linux 8. Users are advised to apply the update after ensuring all previous errata are applied.

Join the discussion

Red Hat has issued a security update for PostgreSQL 16 addressing two vulnerabilities: CVE-2024-4317, which involves missing authorization checks in pg_stats_ext and pg_stats_ext_exprs, and CVE-2024-7348, where relation replacement during pg_dump can execute arbitrary SQL. These issues could allow unauthorized actions within the database system. The update is rated as Important by Red Hat Product Security. The advisory covers Red Hat Enterprise Linux 9 and its various update and support streams. Users are advised to apply the update as detailed in the Red Hat advisory to mitigate these vulnerabilities.

Join the discussion

PostgreSQL versions 14, 15, and 16 prior to 14.12, 15.7, and 16.3 respectively have a vulnerability in the built-in views pg_stats_ext and pg_stats_ext_exprs. These views lack proper authorization checks, allowing unprivileged database users to read statistical data, including most common values from CREATE STATISTICS commands of other users. This exposure may reveal sensitive column values or function results that the user should not access. The vulnerability affects existing installations unless they follow specific upgrade instructions. A patch is available to fix this issue.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2024-4317
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses