CVE-2023-41114
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2023
Last modified:
14/12/2023
Description
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are publicly executable, thus permitting an authenticated user to read any file from the local filesystem or remote system regardless of that user's permissions.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:* | 11.21.32 (excluding) | |
| cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:* | 12.0.0 (including) | 12.16.20 (excluding) |
| cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:* | 13.0.0 (including) | 13.12.17 (excluding) |
| cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:* | 14.0.0 (including) | 14.9.0 (excluding) |
| cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:* | 15.0.0 (including) | 15.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



