VYPR
Medium severity6.5NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026

CVE-2023-41115

CVE-2023-41115

Description

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:*range: <11.21.32
    • (no CPE)
    • (no CPE)range: <11.21.32, <12.16.20, <13.12.16, <14.9.0, <15.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.