Comprehensive data protection for all workloads
Post Reply
mkretzer
Veteran
Posts: 1267
Liked: 456 times
Joined: Dec 17, 2015 7:17 am
Contact:

How risky is running the pre-installed Postgresql without updates really?

Post by mkretzer » 1 person likes this post

Hello,

i am a big fan of updating everything that can pose a security risk and i have seen a lot of Veeam users unhappy with the decision to pre-install Postgresql. I just wonder: Is there a realistic attack scenario where the Postgresql server causes a security risk?

When the Veeam system is non Domain-Joined, Postgresql only listens on localhost (from what i see this is the default setting) and Veeam is on a dedicated server i currently do not see any way to attack that component - or do i miss something?

Markus
tgx
Enthusiast
Posts: 60
Liked: 62 times
Joined: Feb 11, 2019 6:17 pm
Contact:

Re: How risky is running the pre-installed Postgresql without updates really?

Post by tgx »

According to Veeam:

"Note: This vulnerability only impacts domain-joined backup servers."

source: https://www.veeam.com/kb4724
Gostev
Chief Product Officer
Posts: 32374
Liked: 7726 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: How risky is running the pre-installed Postgresql without updates really?

Post by Gostev » 1 person likes this post

mkretzer wrote: Apr 07, 2025 4:36 pmI just wonder: Is there a realistic attack scenario where the Postgresql server causes a security risk?

When the Veeam system is non Domain-Joined, Postgresql only listens on localhost (from what i see this is the default setting) and Veeam is on a dedicated server i currently do not see any way to attack that component - or do i miss something?
Hi, Markus. I believe your thinking is correct. @dzyuzin what is your opinion?
dzyuzin
Veeam Software
Posts: 8
Liked: 8 times
Joined: Oct 20, 2010 4:15 pm
Full Name: Denis Zyuzin
Contact:

Re: How risky is running the pre-installed Postgresql without updates really?

Post by dzyuzin » 1 person likes this post

Can't give generic answer -- that depends on the vulnerability. I would say no latest PostgreSQL CVEs (2024 and 2025) can be exploited in our usage scenario indeed. But if new CVE will allow some sophisticated RCE that doesn't require network interaction, or that can be exploited to elevate privileges -- we can't be so sure, and customers should always strive to use the latest versions of OS/DB and other software installed on critical infrastructure.
garypigott
Service Provider
Posts: 11
Liked: 6 times
Joined: Sep 17, 2018 4:45 pm
Full Name: Gary Pigott
Contact:

Re: How risky is running the pre-installed Postgresql without updates really?

Post by garypigott » 2 people like this post

Even if there's no specific risk, having a CVSS 9.9 vulnerability against an entry in your software catalog triggers an immediate response in a lot of organisations. It just looks bad to leave it there for any length of time. We patched it anyway, same day. I work for an MSP where being down for an hour while we patch everything can be explained. Getting rooted and having all our client's data exposed on the other hand is a company ending event.
Gostev
Chief Product Officer
Posts: 32374
Liked: 7726 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: How risky is running the pre-installed Postgresql without updates really?

Post by Gostev »

You're probably talking about something different that what this topic is about (last Veeam vulnerability vs. recent PostgreSQL vulnerabilities over the last couple of years).
Post Reply

Who is online

Users browsing this forum: Baidu [Spider], Bing [Bot], Google [Bot], Semrush [Bot], sgarga and 35 guests