New CVE in PostgreSQL CVE-2025-8714

UCMUserAZ

Customer
Joined
Dec 19, 2023
Messages
124
Reaction score
215
I am sure you are all aware, but just posting for awareness. Our Security team let us know there is a new PostgreSQL CVE on the DB. CVE-2025-8714 I will patch the Grafana windows server and report results, but just noting they saw it on the 3cx server as well. I let them know we wait for 3cx for updates on the 3cx debian server. Thanks all.
 
I updated PostgreSQL on Grafana windows server to latest and no issues there.
 
Hello @UCMUserAZ,
Thanks for raising this topic,

We are aware of this CVE affecting current postgresql version, but based on its description this affects special command lines tools shipped with the database for maintenance tasks which aren't accessible anyhow to the 3CX users (of any role). One would need to have a remote administrative/SSH access to the machine in the first place to be able to exploit these.
As such after careful review we assessed that the 3cx phone system isn't at risk.

Nevertheless we are planning to update the database in update 8 for windows, and will do also on linux when an update from the official debian repositories will be available so that these alerts can be cleared. In the meantime, no manual actions should be taken from your end nor are needed.
 
Hello @UCMUserAZ,
Thanks for raising this topic,

We are aware of this CVE affecting current postgresql version, but based on its description this affects special command lines tools shipped with the database for maintenance tasks which aren't accessible anyhow to the 3CX users (of any role). One would need to have a remote administrative/SSH access to the machine in the first place to be able to exploit these.
As such after careful review we assessed that the 3cx phone system isn't at risk.

Nevertheless we are planning to update the database in update 8 for windows, and will do also on linux when an update from the official debian repositories will be available so that these alerts can be cleared. In the meantime, no manual actions should be taken from your end nor are needed.
Thank you!
 
Hello @UCMUserAZ,
Thanks for raising this topic,

We are aware of this CVE affecting current postgresql version, but based on its description this affects special command lines tools shipped with the database for maintenance tasks which aren't accessible anyhow to the 3CX users (of any role). One would need to have a remote administrative/SSH access to the machine in the first place to be able to exploit these.
As such after careful review we assessed that the 3cx phone system isn't at risk.

Nevertheless we are planning to update the database in update 8 for windows, and will do also on linux when an update from the official debian repositories will be available so that these alerts can be cleared. In the meantime, no manual actions should be taken from your end nor are needed.
Hi there. Appears the libpq5 is now upgradeable to the fixed version 15.14. Just wondering when you think 3cx will push out? Not to be a pest, just so I can let our Security know as they ask me for status. Thanks in advance.

libpq5/bookworm,now 15.13-0+deb12u1 amd64 [installed,upgradable to: 15.14-0+deb12u1]
 
Thanks for updating. All good now.
 

Forum statistics

Threads
111,954
Messages
589,921
Members
164,851
Latest member
DrunkeMeister