Varonis Warns of Bug Discovered in PostgreSQL PL/Perl
ID: b86e50df-85de-5646-bccf-c588b0c8c3b4
STIX ID: report--b86e50df-85de-5646-bccf-c588b0c8c3b4
Feed Name: Dark Reading
Researchers disclosed CVE-2024-10979, a vulnerability in PostgreSQL's PL/Perl language extension that allows setting arbitrary environment variables in session processes, assigned CVSS 8.8; this can enable arbitrary code execution and additional queries to enumerate system contents. Versions prior to PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected; recommended mitigations are upgrading to the latest minor versions, restricting allowed extensions, and reviewing DDL logs for unrecognized function creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
