Decade-old PostgreSQL flaw turns backup account into a backdoor
Summary
A critical, decade-old vulnerability in PostgreSQL, dubbed PostGREShell, has been discovered that allows attackers with low-privilege replication accounts to execute arbitrary code and gain full database and server compromise. The flaw exists in the database's replication functionality and was present in versions dating back to 2014, with patches released on August 13th.
IFF Assessment
This vulnerability allows attackers to escalate privileges and gain complete control over a PostgreSQL server, representing a significant threat to data security.
Severity
Defender Context
This critical vulnerability highlights the importance of promptly patching database systems, especially those with long-standing codebases. Defenders should prioritize upgrading PostgreSQL to the latest patched versions and review their replication account permissions to mitigate the risk of compromise.