Echo: postgresql-13: security update to 13.17postgresql-17: security update to 17.1-1

medium Tenable Cloud Security Plugin ID 457033

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change
different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION
AUTHORIZATION, or an equivalent feature. The problem arises when an application query uses parameters from
the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or
the current user ID, it may modify or return data as though the session had not used SET ROLE or SET
SESSION AUTHORIZATION. The attacker does not control which incorrect user ID applies. Query text from
less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not
sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are
affected. (CVE-2024-10978)

Solution

Update the postgresql-13 library and its related packages to version 13.17 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-10978

Plugin Details

Severity: Medium

ID: 457033

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.1

Percentile: 53.38

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.7

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2024-10978

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/20/2026

Vulnerability Publication Date: 11/12/2024

Reference Information

CVE: CVE-2024-10978