github pgaudit/set_user REL2_0_1

latest releases: REL4_1_0, REL4_1_0RC1, REL4_0_1...
3 years ago

GUC deprecation and RESET logic bugfixes

  • Fix GUC deprecation logic to stop printing noisy NOTICEs every time
    GUCs are referenced.
  • Appropriately check for RESET SESSION AUTHORIZATION and drop invalid
    reference to RESET USER.

This release addresses CVE-2021-38140:

Potential privilege escalation using RESET SESSION AUTHORIZATION after set_user(). This is now blocked along with RESET ROLE.

Don't miss a new set_user release

NewReleases is sending notifications on new releases.