Splunk Enterprise Security

Postgres vulnerability CVE-2025-1094

Dolly
Engager

Why do we find postgres in /apps/splunk/splunkforwarder/quarantined_files/bin/postgres even if we have upgraded to 9.4.3. Splunk must have moved this? If yes why?

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Dolly 

postgres was incorrectly included in some 9.4.x UF builds, therefore if you are upgrading from one of these builds then the UF will "quarantine" the postgres binary as its not required/expected in the UF bin directory. 

You can safely remove the postgres binary from within the quarantine directory as it is not needed. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Dolly
Engager

Sorry, this didn't help me in understanding Why do we find postgres in /apps/splunk/splunkforwarder/quarantined_files/bin/postgres even if we have upgraded to 9.4.3?

 

0 Karma

thahir
Communicator

Hi @Dolly ,

Splunk recently (especially in newer 9.x versions) introduced mechanisms to quarantine suspicious or unexpected binaries during startup or upgrade.

As part of App Integrity Checking or Quarantine subsystem, it moved that binary out of active paths into quarantined_files for security reasons.

  • During an upgrade, Splunk validates installed apps and files.

  • If it finds unexpected binaries (especially those with execution permissions or high-risk names like postgres, bash, sh), it moves them to quarantined_files/ to prevent unintended execution.

 

 

kiran_panchavat
Champion

@Dolly 

Refer the below link. 

Solved: Postgresql on Splunk Enterprise - Splunk Community

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...