Splunk Enterprise Security

Postgres vulnerability CVE-2025-1094

Dolly
Engager

Why do we find postgres in /apps/splunk/splunkforwarder/quarantined_files/bin/postgres even if we have upgraded to 9.4.3. Splunk must have moved this? If yes why?

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Dolly 

postgres was incorrectly included in some 9.4.x UF builds, therefore if you are upgrading from one of these builds then the UF will "quarantine" the postgres binary as its not required/expected in the UF bin directory. 

You can safely remove the postgres binary from within the quarantine directory as it is not needed. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Dolly
Engager

Sorry, this didn't help me in understanding Why do we find postgres in /apps/splunk/splunkforwarder/quarantined_files/bin/postgres even if we have upgraded to 9.4.3?

 

0 Karma

thahir
Contributor

Hi @Dolly ,

Splunk recently (especially in newer 9.x versions) introduced mechanisms to quarantine suspicious or unexpected binaries during startup or upgrade.

As part of App Integrity Checking or Quarantine subsystem, it moved that binary out of active paths into quarantined_files for security reasons.

  • During an upgrade, Splunk validates installed apps and files.

  • If it finds unexpected binaries (especially those with execution permissions or high-risk names like postgres, bash, sh), it moves them to quarantined_files/ to prevent unintended execution.

 

 

kiran_panchavat
SplunkTrust
SplunkTrust

@Dolly 

Refer the below link. 

Solved: Postgresql on Splunk Enterprise - Splunk Community

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...