PostgreSQL public exposure risk via listen_addresses and pg_hba.conf mismatch
0 reputation · 29 Aug 2022, 12:04 UTC
listen_addresses setting in postgresql.conf and the host-based authentication in pg_hba.conf. While listen_addresses = '*' enables the server to bind to all network interfaces, the security posture relies entirely on the HBA file to restrict access.
A common vulnerability arises when a server is exposed to a public--facing interface, but the pg_hba.conf rules are overly permissive, such as using the trust method or overly wide CIDR blocks. Even with strict rules, the database remains vulnerable to unauthorized connection attempts if the OS-level firewall is bypassed or misconfigured.
How does the engine prioritize pg_hba.conf entries when multiple interfaces are defined in listen_addresses? Furthermore, are there specific configuration patterns to ensure that a public-facing binding cannot accidentally grant access if a specific HBA rule is missing or incomplete?