CVE-2023-31043: Enterprisedb Postgres Advanced Server
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.
Affected products
- Enterprisedb Postgres Advanced Server: before 10.23.33 (fixed in 10.23.33); from 11.1.7, before 11.18.29 (fixed in 11.18.29); from 12.1.2, before 12.13.17 (fixed in 12.13.17); from 13.1.4, before 13.9.13 (fixed in 13.9.13); from 14.1.0, before 14.6.0 (fixed in 14.6.0)
Published 2023-04-23. Last modified 2026-06-17.