CVE-2024-0985

Name
CVE-2024-0985
Description
Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 https://www.postgresql.org/support/security/CVE-2024-0985/
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 https://lists.debian.org/debian-lts-announce/2024/03/msg00017.html
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 https://saites.dev/projects/personal/postgres-cve-2024-0985/
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20241220-0005/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* postgresql >= 12.0 < 12.18
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* postgresql >= 13.0 < 13.14
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* postgresql >= 14.0 < 14.11
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* postgresql >= 15.0 < 15.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
postgresql17 edge-main 16.2-r0 None fixed
postgresql16 edge-main 16.2-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql16 edge-community 16.2-r0 None fixed
postgresql16 3.22-main 16.2-r0 None fixed
postgresql16 3.21-main 16.2-r0 None fixed
postgresql16 3.20-main 16.2-r0 None fixed
postgresql16 3.19-main 16.2-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql15 edge-main 15.6-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql15 edge-community 15.6-r0 None fixed
postgresql15 3.22-community 15.6-r0 None fixed
postgresql15 3.21-community 15.6-r0 None fixed
postgresql15 3.20-main 15.6-r0 None fixed
postgresql15 3.19-main 15.6-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql15 3.18-main 15.6-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql15 3.17-main 15.6-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql14 edge-community 14.11-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql14 3.20-community 14.11-r0 None fixed
postgresql14 3.19-community 14.11-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql14 3.18-main 14.11-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql14 3.17-main 14.11-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql13 edge-community 13.14-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql13 3.19-community 13.14-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
postgresql edge-main 14.1-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
postgresql edge-main 13.4-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
postgresql edge-main 13.3-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
postgresql edge-main 13.2-r0 None possibly vulnerable
postgresql edge-main 12.5-r0 None possibly vulnerable
postgresql edge-main 12.4-r0 None possibly vulnerable
postgresql edge-main 12.2-r0 None possibly vulnerable