PostgreSQL Vulnerability Security Update Advisory (CVE-2024-0985)

Overview

 

PostgreSQL(https://www.postgresql.org/) has released a security update that fixes vulnerabilities in its products. Users of affected products are advised to update to the latest version.

 

Affected Products

 

PostgreSQL 15

PostgreSQL 14

PostgreSQL 13

PostgreSQL 12

 

Resolved Vulnerabilities

 

Arbitrary SQL Execution Vulnerability in PostgreSQL (CVE-2024-0985, CVSS 8.0) [1]

 

Vulnerability Patches

 

Please follow the security advisory published on February 06, 2016 to update to the appropriate version and the latest version.

PostgreSQL 15.6

PostgreSQL 14.11

PostgreSQL 13.14

PostgreSQL 12.18

 

Referenced Sites

 

[1] CVE-2024-0985 : PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL

https://www.postgresql.org/support/security/CVE-2024-0985/