• Noah Misch's avatar
    Empty search_path in logical replication apply worker and walsender. · 11da9702
    Noah Misch authored
    This is like CVE-2018-1058 commit
    582edc36.  Today, a malicious user of a
    publisher or subscriber database can invoke arbitrary SQL functions
    under an identity running replication, often a superuser.  This fix may
    cause "does not exist" or "no schema has been selected to create in"
    errors in a replication process.  After upgrading, consider watching
    server logs for these errors.  Objects accruing schema qualification in
    the wake of the earlier commit are unlikely to need further correction.
    Back-patch to v10, which introduced logical replication.
    
    Security: CVE-2020-14349
    11da9702
libpqwalreceiver.c 27.1 KB