45b8716b-c707-11eb-b9a0-6805ca0b3d42pglogical -- shell command injection in pglogical.create_subscription()

2ndQuadrant reports:

  • Fix pg_dump/pg_restore execution (CVE-2021-3515)

    Correctly escape the connection string for both pg_dump and pg_restore so that exotic database and user names are handled correctly.

    Reported by Pedro Gallegos

Discovery 2021-06-01
Entry 2021-06-06
lt 2.3.4