Description
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2801 Vulnerability (CVE-2019-2801)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2271)
Apache Traffic Server Other Vulnerability (CVE-2019-9513)
OpenSSL Cryptographic Issues Vulnerability (CVE-2014-3470)
WordPress Plugin Stop User Enumeration User Enumeration (1.3.4)