Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether certain files exist on disk, what errors if any occur when attempting to read them, and some limited information about their contents (regardless of permissions). This can occur when a superuser has configured one or more directories for filesystem access via CREATE DIRECTORY and adopted certain non-default settings for log_line_prefix and log_connections.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
EnterpriseDB Postgres Advanced Server 安全漏洞
Vulnerability Description
EnterpriseDB Postgres Advanced Server(EPAS)是美国EnterpriseDB公司的一个应用程序。用于扩展 Postgres 数据库的功能。 EnterpriseDB Postgres Advanced Server 存在安全漏洞,该漏洞源于允许经过身份验证的用户获取某些信息。
CVSS Information
N/A
Vulnerability Type
N/A