CVE-2023-31043
23.04.2023, 20:15
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.Enginsight
Vendor | Product | Version |
---|---|---|
enterprisedb | postgres_advanced_server | 𝑥 < 10.23.33 |
enterprisedb | postgres_advanced_server | 11.1.7 ≤ 𝑥 < 11.18.29 |
enterprisedb | postgres_advanced_server | 12.1.2 ≤ 𝑥 < 12.13.17 |
enterprisedb | postgres_advanced_server | 13.1.4 ≤ 𝑥 < 13.9.13 |
enterprisedb | postgres_advanced_server | 14.1.0 ≤ 𝑥 < 14.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
- CWE-521 - Weak Password RequirementsThe product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
References