set_user 2.0.1 released

Поиск
Список
Период
Сортировка
От Crunchy Data via PostgreSQL Announce
Тема set_user 2.0.1 released
Дата
Msg-id 163016845889.699.3584067677876520138@wrigleys.postgresql.org
обсуждение исходный текст
Список pgsql-announce
 

set_user 2.0.1 released

Crunchy Data is pleased to announce the release of the PostgreSQL set_user Extension module version 2.0.1.

This release contains one security fix and one other bug fix. It is highly recommended to update to this version of set_user as soon as possible.

Security Issues

  • CVE-2021-38140: Fixed potential privilege escalation using RESET SESSION AUTHORIZATION after calling set_user(). This is now blocked along with RESET ROLE.

Fixes

  • Fix GUC deprecation logic to stop printing noisy NOTICEs every time GUCs are referenced.

Links

Crunchy Data is proud to support the development and maintenance of set_user).

 

В списке pgsql-announce по дате отправления:

Предыдущее
От: MigOps via PostgreSQL Announce
Дата:
Сообщение: PostgreSQL DBMS_JOB compatibility extension
Следующее
От: Red Hat via PostgreSQL Announce
Дата:
Сообщение: pgmoneta 0.5.0