Echo: postgresql-13: security update to 13.17postgresql-17: security update to 17.1

medium Tenable Cloud Security Plugin ID 459075

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change
different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row
security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or
SQL-language function references a table with a row-level security policy. This has the same consequences
as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases
where role-specific policies are used and a given query is planned under one role and then executed under
other roles. This scenario can happen under security definer functions or when a common user and query is
planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a
user to complete otherwise-forbidden reads and modifications. This affects only databases that have used
CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular
application's pattern of query plan reuse, user ID changes, and role-specific row security policies.
Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. (CVE-2024-10976)

Solution

Update the postgresql-13 library and its related packages to version 13.17 or later.

See Also

https://advisory.echohq.com/cve/CVE-2024-10976

Plugin Details

Severity: Medium

ID: 459075

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.51

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2024-10976

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/20/2026

Vulnerability Publication Date: 11/12/2024

Reference Information

CVE: CVE-2024-10976