Alpine: postgresql: security update to 11.9-r0

high Tenable Self-Hosted Container Security Plugin ID 406468

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize
the search_path during logical replication. An authenticated attacker could use this flaw in an attack
similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for
replication. (CVE-2020-14349)

- It was found that some PostgreSQL extensions did not use search_path safely in their installation script.
An attacker with sufficient privileges could use this flaw to trick an administrator into executing a
specially crafted script, during the installation or update of such extension. This affects PostgreSQL
versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23. (CVE-2020-14350)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-14349

https://security.alpinelinux.org/vuln/CVE-2020-14350

Plugin Details

Severity: High

ID: 406468

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 3/13/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2020-14349

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2020-14350

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/13/2020

Reference Information

CVE: CVE-2020-14349, CVE-2020-14350

IAVB: 2020-B-0047-S