SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1901

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

MEDIUM 4.0EPSS 3.30%

Does this matter?

Lower severity and a low EPSS score (3.30%). Track it; it rarely justifies an emergency change on its own.

Description

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS
3.30% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
postgresql/postgresql · canonical/ubuntu linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.