-
- Lurker
- Posts: 1
- Liked: never
- Joined: Aug 18, 2025 1:29 pm
- Contact:
Vulnerable version of PostgreSQL bundled with VBR 12.3.2
Hi forum folks,
Our Nessus Scanner is flagging CVE-2025-1094 on our VBR servers due to PostgreSQL being at a vulnerable version. The scanner is stating that PostgreSQL 13.x < 13.19 / 14.x < 14.16 / 15.x < 15.11 / 16.x < 16.7 / 17.x < 17.3 SQLi. Are there any plans for version 12.3.3 or version 13 being released soon with an updated PostgreSQL version? Or a workaround for this? Since we are federal, these vulnerability flags leave a stain. Thanks!
Our Nessus Scanner is flagging CVE-2025-1094 on our VBR servers due to PostgreSQL being at a vulnerable version. The scanner is stating that PostgreSQL 13.x < 13.19 / 14.x < 14.16 / 15.x < 15.11 / 16.x < 16.7 / 17.x < 17.3 SQLi. Are there any plans for version 12.3.3 or version 13 being released soon with an updated PostgreSQL version? Or a workaround for this? Since we are federal, these vulnerability flags leave a stain. Thanks!
-
- Chief Product Officer
- Posts: 32411
- Liked: 7777 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
Hi, you should just update PostgreSQL manually. As even when 12.3.3 comes out with a newer PostgreSQL version embedded, it won't be able to update existing PostgreSQL installs to the same version. Thanks
-
- Service Provider
- Posts: 635
- Liked: 158 times
- Joined: Apr 03, 2019 6:53 am
- Full Name: Karsten Meja
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
kb4386
btw. postgresql 15.x is only supported up to Server 2019. what are your plans for that?
btw. postgresql 15.x is only supported up to Server 2019. what are your plans for that?
-
- Chief Product Officer
- Posts: 32411
- Liked: 7777 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
No specific plans for V12. As before, we'll keep testing all future V12 maintenance releases on all Windows Server versions we officially support. If we ever encounter an issue that is specific to using PosgreSQL 15 on some Windows Server version, we will decide what to do depending on the issue.
Now, V13 comes with the latest PostgreSQL version of course, specifically 17.6.
Now, V13 comes with the latest PostgreSQL version of course, specifically 17.6.
-
- Enthusiast
- Posts: 84
- Liked: 6 times
- Joined: Sep 07, 2014 11:15 am
- Full Name: Stephan G
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
This site states that only the installers are tested on these plattforms.
https://www.postgresql.org/download/windows/
It does not say that PostgreSQL does not run on Win2022 or higher.
It says that they might run on higher versions that are comparable.
https://www.postgresql.org/download/windows/
It does not say that PostgreSQL does not run on Win2022 or higher.
It says that they might run on higher versions that are comparable.
-
- Service Provider
- Posts: 58
- Liked: 7 times
- Joined: May 04, 2018 1:54 pm
- Full Name: Peter Kuikman
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
Interesting, and this makes me thinking. In cases where you are using an external postgres database, the embedded postgres install in VBR will still be vulnerable?
-
- Enthusiast
- Posts: 84
- Liked: 6 times
- Joined: Sep 07, 2014 11:15 am
- Full Name: Stephan G
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
Why would you keep something running that you are not using?
And isn't it the same with every other software?
When i download the Microsoft Win11 iso - most of the time i have to perform the latest updates afterwards.
And isn't it the same with every other software?
When i download the Microsoft Win11 iso - most of the time i have to perform the latest updates afterwards.
-
- Influencer
- Posts: 23
- Liked: 9 times
- Joined: Oct 09, 2024 6:17 pm
- Contact:
-
- Service Provider
- Posts: 38
- Liked: 10 times
- Joined: Sep 13, 2018 3:00 pm
- Full Name: Michael Lumsden
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
Is it possible in the future VBR updates can update postgres to at least the version included in the redistributable folder in the iso? Other Veeam products, such as Veeam Backup for Azure update postgres when you check for updates. I like the move to postgres, but it was nice that SQL patching happened with Windows updates.
-
- Chief Product Officer
- Posts: 32411
- Liked: 7777 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: Vulnerable version of PostgreSQL bundled with VBR 12.3.2
This requires a "software appliance" experience that is coming to VBR with V13. Same idea as Veeam Backup for Azure appliance with the same Veeam Updater tech to maintain base OS, our software and 3rd party components.
Who is online
Users browsing this forum: Amazon [Bot], Bing [Bot] and 79 guests