PostGREShell
We are aware of Postgres replication vulnerability known as ‘PostGREShell’
Within a standard VQ Conference Manager (VQCM) instance the PostgreSQL instance is not externally exposed, therefore requiring CLI access to the VQCM itself to attempt to exploit. At the point of access an attacker can already carry code execution on the host system.
On a VQCM High Availability (HA) deployment an attacker would need to have credentials for a valid replication user, this would initially require access to a VQCM HA instance, which again would allow the attacker to carry out code execution without exploitation of this vulnerability in the first instance.
This vulnerability impacts all VQCM HA releases, we are currently working on a VQCM HA release which will have a fixed version of the PostgreSQL instance and will update customers once this is available. Customers with existing VQCM HA instances that they can not upgrade or who wish to discuss this CVE and their own risk profile should email security@vqcomms.com

