<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Patch NPrinting in Qlik NPrinting</title>
    <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2425456#M41124</link>
    <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Traduction" data-ved="2ahUKEwj25Ofp-NCEAxUxU6QEHVq5APwQ3ewLegQIBRAU"&gt;&lt;SPAN class="Y2IQFc"&gt;Is there a patch planned for NPrinting to address the PostgreSQL security problem?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 16:15:27 GMT</pubDate>
    <dc:creator>jvandrot</dc:creator>
    <dc:date>2024-02-29T16:15:27Z</dc:date>
    <item>
      <title>Patch NPrinting</title>
      <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2425456#M41124</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Traduction" data-ved="2ahUKEwj25Ofp-NCEAxUxU6QEHVq5APwQ3ewLegQIBRAU"&gt;&lt;SPAN class="Y2IQFc"&gt;Is there a patch planned for NPrinting to address the PostgreSQL security problem?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:15:27 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2425456#M41124</guid>
      <dc:creator>jvandrot</dc:creator>
      <dc:date>2024-02-29T16:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Patch NPrinting</title>
      <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2425514#M41125</link>
      <description>&lt;P&gt;Which problem are you referring to?&amp;nbsp; There was a postgresql upgrade included in NPrinting February 2024.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JonnyPoole_0-1709228861149.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/161016iA02A15B08A3EE12A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JonnyPoole_0-1709228861149.png" alt="JonnyPoole_0-1709228861149.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 17:48:09 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2425514#M41125</guid>
      <dc:creator>JonnyPoole</dc:creator>
      <dc:date>2024-02-29T17:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Patch NPrinting</title>
      <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426443#M41137</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm reffering to the security breach dated from Februray 8th, which is fixed on update 13.14&lt;/P&gt;
&lt;P&gt;The february version is 13.13&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.postgresql.org/support/security/" target="_blank"&gt;https://www.postgresql.org/support/security/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table table-striped"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;Reference&lt;/TH&gt;
&lt;TH&gt;Affected&lt;/TH&gt;
&lt;TH&gt;Fixed&lt;/TH&gt;
&lt;TH&gt;&lt;A href="https://www.postgresql.org/support/security/#comp" target="_blank"&gt;Component&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;amp; CVSS v3 Base Score&lt;/TH&gt;
&lt;TH&gt;Description&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN class="nobr"&gt;&lt;A href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank"&gt;CVE-2024-0985&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://www.postgresql.org/about/news/postgresql-162-156-1411-1314-and-1218-released-2807/" target="_blank"&gt;Announcement&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;15, 14, 13, 12&lt;/TD&gt;
&lt;TD&gt;15.6, 14.11, 13.14, 12.18&lt;/TD&gt;
&lt;TD&gt;core server&lt;BR /&gt;&lt;A href="https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank"&gt;8.0&lt;/A&gt;&lt;BR /&gt;&lt;SPAN class="cvssvector"&gt;AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.postgresql.org/support/security/CVE-2024-0985/" target="_blank"&gt;more details&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 04 Mar 2024 08:37:16 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426443#M41137</guid>
      <dc:creator>jvandrot</dc:creator>
      <dc:date>2024-03-04T08:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Patch NPrinting</title>
      <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426738#M41138</link>
      <description>&lt;P&gt;Thanks for the post&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/193375"&gt;@jvandrot&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Qlik NPrinting product team and our security team are in constant communication around various identified security topics.&amp;nbsp; This item is on our radar and is being planned for resolution in an Service Release for both the Qlik NPrinting May 2023 and Qlik NPrinting February 2024 build lines.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the mean time it is worth noting that this vulnerability is not exploitable in Qlik NPrinting as the product does not allow users to construct such kind of query required to exploit the vulnerability. Even though the product accepts user input (which is sanitized as part of a defense-in-depth strategy), there is no way in the product to create the kind of query required for exploitation in this scenario.&lt;BR /&gt;A theoretical attack would require an advisory to get direct access to the NPrinting database as well as privileged filesystem access in addition to several other preconditions be met. If such escalated privileged access would be possible, there would other ways to yield more gain or access.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 16:35:23 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426738#M41138</guid>
      <dc:creator>Andrew_Kruger</dc:creator>
      <dc:date>2024-03-04T16:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Patch NPrinting</title>
      <link>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426826#M41139</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/193375"&gt;@jvandrot&lt;/a&gt;&amp;nbsp;R&amp;amp;D will be doing a Service Release of NP with the 13.14 version, but like Andrew said its not a security concern for NP&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 21:28:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Qlik-NPrinting/Patch-NPrinting/m-p/2426826#M41139</guid>
      <dc:creator>David_Friend</dc:creator>
      <dc:date>2024-03-04T21:28:25Z</dc:date>
    </item>
  </channel>
</rss>

