From: | "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com> |
---|---|
To: | Bruce Momjian <bruce(at)momjian(dot)us> |
Cc: | Kishore Isaac <k(dot)isaac(at)loccioni(dot)com>, "pgsql-bugs(at)lists(dot)postgresql(dot)org" <pgsql-bugs(at)lists(dot)postgresql(dot)org> |
Subject: | Re: Tenable Report Issue even after upgrading to correct Postgres version |
Date: | 2021-11-11 17:54:43 |
Message-ID: | CAKFQuwaTHFJvdPMn_TrSVfk6Y7PidmMYRErFZMphU_aU5F4ovQ@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-bugs |
On Thursday, November 11, 2021, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
> On Thu, Nov 11, 2021 at 03:49:29PM +0000, Kishore Isaac wrote:
> >
> >
> > We were informed by a customer using Tenable reports that we needed to
> upgrade
> > Postgres from 12.2 to 12.7 due to vulnerability issues. We have since
> upgraded
> > to the requested version of Postgres (12.7) but the Tenable report scans
> still
> > show that the version is 12.2. After reaching out the Tenable, we found
> that
> > the version information is not updated in the system registry where
> Tenable is
> > pulling the information from. Is there any resolution for this?
> >
> >
> >
> > Below is the registry information:
>
> Uh, I have no idea what Tenable is, which I think means we don't control
> that way of distributing Postgres.
>
IIUC Tenable is just a system scanner. Apparently whomever built the
Windows installer/upgrade binary for this customer (likely EDB) puts
version info, during initial install, into the Window’s Registry but
doesn’t update that information upon performing a minor release patch.
This seems like a bug, though not of the core project but the distributor.
David J.
From | Date | Subject | |
---|---|---|---|
Next Message | Erki Eessaar | 2021-11-11 18:29:10 | Query optimization - table elimination in case of LEFT JOIN but not in case of INNER JOIN |
Previous Message | Bruce Momjian | 2021-11-11 17:48:39 | Re: Tenable Report Issue even after upgrading to correct Postgres version |