pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.

pgsql: Reject substituting extension schemas or owners matching ["$'\].

2023-08-10 Thread Noah Misch
Reject substituting extension schemas or owners matching ["$'\]. Substituting such values in extension scripts facilitated SQL injection when @extowner@, @extschema@, or @extschema:...@ appeared inside a quoting construct (dollar quoting, '', or ""). No bundled extension was vulnerable.