vulnerability

FreeBSD: VID-45b8716b-c707-11eb-b9a0-6805ca0b3d42 (CVE-2021-3515): pglogical -- shell command injection in pglogical.create_subscription()

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 6, 2021
Added
Nov 4, 2022
Modified
Mar 25, 2026

Description

2ndQuadrant reports: Fix pg_dump/pg_restore execution (CVE-2021-3515) Correctly escape the connection string for both pg_dump and pg_restore so that exotic database and user names are handled correctly. Reported by Pedro Gallegos

Solution

freebsd-upgrade-package-pglogical
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.