#VU82943 Permissions, Privileges, and Access Controls in PostgreSQL - CVE-2023-5870
Published: November 9, 2023
PostgreSQL
PostgreSQL Global Development Group
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to pg_cancel_backend rolse signals background workers, including the logical replication launcher, autovacuum workers and the autovacuum launcher. A remote privileged user can abuse this behavior and perform a denial of service (DoS) attack.