pgaudit/set_user

pgaudit/set_user

Releases21
Frequency5 months 3 weeks
Last Release
Stars77
PostgreSQL extension allowing privilege escalation with enhanced logging and control

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.

9.8 CRITICAL7.5 HIGH

The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().