Open Source PostgreSQL version 15.12 affected by CVE-2025-8713 Security Issues

oliveifc

Premier Customer
Joined
Nov 11, 2014
Messages
6
Reaction score
0
Hello,
Our SOC team has advised 3CX has Open Source PostgreSQL version 15.12 installed, that is currently under Security Issues, CVE-2025-8713 PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table.
Is anyone aware how to upgrade it to unaffected version?
Current 3CX installation are running 20.0.6.724, Windows OS.
Thanks

PostgreSQL CVE-2025-8713 dated 2025-08-14
https://www.postgresql.org/support/security/CVE-2025-8713/
 
Hi, thanks for reporting, we are checking internally...
 
Last edited:
Hello oliveifc,

Thanks for the question,

Please note that the severity of this CVE varies greatly depending on how the database has been configured. In our case the database is by default secured by various means such as its ports not being exposed to the outside, accessible to localhost processes only, unique credentials for each installation, strict queries parser inbuilt, etc.
As such after careful review we assessed that the 3cx phone system isn't at risk.

Nevertheless we are planning to update the database in update 8 so that these alerts can be cleared. In the meantime, no manual actions should be taken from your end nor are needed.
 

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86