Dear Xihe (Halo) Database Users:
Hello. We greatly appreciate your continued support and trust in the Xihe (Halo) database. To continuously improve product security and stability, we recently conducted a comprehensive security audit of the Xihe (Halo) database and discovered the following two important security vulnerabilities. To ensure your data security, we have urgently developed corresponding patches and fixed these vulnerabilities. The details are announced as follows:
I. Vulnerability Details
(I) pg_stats_ext and pg_stats_ext_exprs Views Missing Authentication Vulnerability
Vulnerability ID: CVE-2024-4317
Risk Level: Low
Vulnerability Description: In certain versions of the Xihe (Halo) database, the pg_stats_ext and pg_stats_ext_exprs views have an authentication deficiency. This allows unauthorized users to access and view statistical information in these views, potentially leaking sensitive data or affecting database security.
Remediation Measures: We have enhanced the authentication mechanism for these two views, ensuring only users with appropriate permissions can access these views.
(II) Privilege Escalation Vulnerability via REFRESH MATERIALIZED VIEW CONCURRENTLY
Vulnerability ID: CVE-2024-0985
Risk Level: High
Vulnerability Description: In certain versions of the Xihe (Halo) database, through the privilege escalation vulnerability in REFRESH MATERIALIZED VIEW CONCURRENTLY, object creators can bypass permission checks and execute arbitrary functions. This may lead to security issues such as unauthorized code execution and data leakage.
Remediation Measures: We have optimized permission control for REFRESH MATERIALIZED VIEW CONCURRENTLY operations, ensuring only users with appropriate permissions can execute this operation.
II. Patch Update
To fix the above vulnerabilities, we have released critical patches for the Xihe (Halo) database. If you have version update requirements, please contact our business team.
III. Security Recommendations
Regular Updates: Please regularly follow the Xihe (Halo) database update announcements and promptly apply the latest patches and version updates.
Permission Management: Please strengthen the permission management of the database system, ensuring only users with appropriate permissions can access and operate the database.
Security Audit: Please regularly conduct security audits and vulnerability scans of the database system to promptly discover and fix potential security issues.