logo

Varonis Warns of Bug Discovered in PostgreSQL PL/Perl

ID: b86e50df-85de-5646-bccf-c588b0c8c3b4

STIX ID: report--b86e50df-85de-5646-bccf-c588b0c8c3b4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-11-14

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers disclosed CVE-2024-10979, a vulnerability in PostgreSQL's PL/Perl language extension that allows setting arbitrary environment variables in session processes, assigned CVSS 8.8; this can enable arbitrary code execution and additional queries to enumerate system contents. Versions prior to PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected; recommended mitigations are upgrading to the latest minor versions, restricting allowed extensions, and reviewing DDL logs for unrecognized function creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.