Comprehensive data protection for all workloads
Post Reply
bc345346
Lurker
Posts: 1
Liked: never
Joined: Aug 18, 2025 1:29 pm
Contact:

Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by bc345346 »

Hi forum folks,

Our Nessus Scanner is flagging CVE-2025-1094 on our VBR servers due to PostgreSQL being at a vulnerable version. The scanner is stating that PostgreSQL 13.x < 13.19 / 14.x < 14.16 / 15.x < 15.11 / 16.x < 16.7 / 17.x < 17.3 SQLi. Are there any plans for version 12.3.3 or version 13 being released soon with an updated PostgreSQL version? Or a workaround for this? Since we are federal, these vulnerability flags leave a stain. Thanks!
Gostev
Chief Product Officer
Posts: 32411
Liked: 7777 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by Gostev » 1 person likes this post

Hi, you should just update PostgreSQL manually. As even when 12.3.3 comes out with a newer PostgreSQL version embedded, it won't be able to update existing PostgreSQL installs to the same version. Thanks
karsten123
Service Provider
Posts: 635
Liked: 158 times
Joined: Apr 03, 2019 6:53 am
Full Name: Karsten Meja
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by karsten123 »

kb4386
btw. postgresql 15.x is only supported up to Server 2019. what are your plans for that?
Gostev
Chief Product Officer
Posts: 32411
Liked: 7777 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by Gostev »

No specific plans for V12. As before, we'll keep testing all future V12 maintenance releases on all Windows Server versions we officially support. If we ever encounter an issue that is specific to using PosgreSQL 15 on some Windows Server version, we will decide what to do depending on the issue.

Now, V13 comes with the latest PostgreSQL version of course, specifically 17.6.
StephanG
Enthusiast
Posts: 84
Liked: 6 times
Joined: Sep 07, 2014 11:15 am
Full Name: Stephan G
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by StephanG »

This site states that only the installers are tested on these plattforms.
https://www.postgresql.org/download/windows/

It does not say that PostgreSQL does not run on Win2022 or higher.
It says that they might run on higher versions that are comparable.
pkuikman
Service Provider
Posts: 58
Liked: 7 times
Joined: May 04, 2018 1:54 pm
Full Name: Peter Kuikman
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by pkuikman »

Interesting, and this makes me thinking. In cases where you are using an external postgres database, the embedded postgres install in VBR will still be vulnerable?
StephanG
Enthusiast
Posts: 84
Liked: 6 times
Joined: Sep 07, 2014 11:15 am
Full Name: Stephan G
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by StephanG » 1 person likes this post

Why would you keep something running that you are not using?

And isn't it the same with every other software?
When i download the Microsoft Win11 iso - most of the time i have to perform the latest updates afterwards.
FCU_JE
Influencer
Posts: 23
Liked: 9 times
Joined: Oct 09, 2024 6:17 pm
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by FCU_JE »

I hope my old comment helps in some way:

post540752.html#p540752
mlumsden76
Service Provider
Posts: 38
Liked: 10 times
Joined: Sep 13, 2018 3:00 pm
Full Name: Michael Lumsden
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by mlumsden76 »

Gostev wrote: Aug 18, 2025 6:58 pm Hi, you should just update PostgreSQL manually. As even when 12.3.3 comes out with a newer PostgreSQL version embedded, it won't be able to update existing PostgreSQL installs to the same version. Thanks
Is it possible in the future VBR updates can update postgres to at least the version included in the redistributable folder in the iso? Other Veeam products, such as Veeam Backup for Azure update postgres when you check for updates. I like the move to postgres, but it was nice that SQL patching happened with Windows updates.
Gostev
Chief Product Officer
Posts: 32411
Liked: 7777 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2

Post by Gostev »

This requires a "software appliance" experience that is coming to VBR with V13. Same idea as Veeam Backup for Azure appliance with the same Veeam Updater tech to maintain base OS, our software and 3rd party components.
Post Reply

Who is online

Users browsing this forum: Google [Bot] and 77 guests