Security Announcement

Xihe (Halo) Database Critical Patch Update Announcement - June 2024

S
Security Response Center
June 20, 2024

Dear Xihe (Halo) Database Users:

Hello. We greatly appreciate your continued support and trust in the Xihe (Halo) database. To continuously improve product security and stability, we recently conducted a comprehensive security audit of the Xihe (Halo) database and discovered the following two important security vulnerabilities. To ensure your data security, we have urgently developed corresponding patches and fixed these vulnerabilities. The details are announced as follows:

I. Vulnerability Details

(I) pg_stats_ext and pg_stats_ext_exprs Views Missing Authentication Vulnerability

Vulnerability ID: CVE-2024-4317

Risk Level: Low

Vulnerability Description: In certain versions of the Xihe (Halo) database, the pg_stats_ext and pg_stats_ext_exprs views have an authentication deficiency. This allows unauthorized users to access and view statistical information in these views, potentially leaking sensitive data or affecting database security.

Remediation Measures: We have enhanced the authentication mechanism for these two views, ensuring only users with appropriate permissions can access these views.

(II) Privilege Escalation Vulnerability via REFRESH MATERIALIZED VIEW CONCURRENTLY

Vulnerability ID: CVE-2024-0985

Risk Level: High

Vulnerability Description: In certain versions of the Xihe (Halo) database, through the privilege escalation vulnerability in REFRESH MATERIALIZED VIEW CONCURRENTLY, object creators can bypass permission checks and execute arbitrary functions. This may lead to security issues such as unauthorized code execution and data leakage.

Remediation Measures: We have optimized permission control for REFRESH MATERIALIZED VIEW CONCURRENTLY operations, ensuring only users with appropriate permissions can execute this operation.

II. Patch Update

To fix the above vulnerabilities, we have released critical patches for the Xihe (Halo) database. If you have version update requirements, please contact our business team.

III. Security Recommendations

Regular Updates: Please regularly follow the Xihe (Halo) database update announcements and promptly apply the latest patches and version updates.

Permission Management: Please strengthen the permission management of the database system, ensuring only users with appropriate permissions can access and operate the database.

Security Audit: Please regularly conduct security audits and vulnerability scans of the database system to promptly discover and fix potential security issues.


Latest Articles

Security Announcement
April 11, 2025

Xihe (Halo) Database Critical Patch Update Announcement - April 2025

Security Announcement
December 18, 2023

Xihe (Halo) Database Critical Patch Update Announcement - December 2023

Kernel Technology
November 10, 2023

Kernel Technology Revealed: Query Tree Node Reentrant Read Technology