Impact
The Prometheus postgres_exporter bundled with Canonical’s postgresql-operator writes the dedicated monitoring user's password to its logs whenever a database connection error occurs. This violates the principle of least privilege for logging and exposes login information, enabling an adversary who can read the logs to acquire a read‑only pg_monitor account. The vulnerability is a straightforward practice of recording sensitive data in logs (CWE‑532).
Affected Systems
Canonical’s postgresql-operator charm, prior to the patch updates, on both the dev track (revisions 1189 for arm64 and 1190 for amd64) and the stable track (revisions 1216 for arm64 and 1217 for amd64). Any deployment of these earlier revisions that runs the postgres_exporter component is impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS data is available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an actor to obtain read access to the exporter’s log files; no external network exploitation surface is known. If log access is compromised, the attacker gains a monitored database account, which can read database metadata and potentially pivot to further database operations.
OpenCVE Enrichment