A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.

Version Information

Affected Version Fixed In
8.2 8.2.4
8.1 8.1.9
8.0 8.0.13
7.4 7.4.17
7.3 7.3.19

