All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-14 15:44
Updated : 2024-05-14 16:11
NVD link : CVE-2024-4545
Mitre link : CVE-2024-4545
CVE.ORG link : CVE-2024-4545
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management