{"id":"CVE-2007-2138","year":2007,"sequence":2138,"component":"","score":null,"cvss_version":"","vector":"","first_published":null,"source_url":"https://www.postgresql.org/support/security/CVE-2007-2138/","facts":{"affected":{"7.3":"7.3","7.4":"7.4","8.0":"8.0","8.1":"8.1","8.2":"8.2"},"component":"","cvss_version":"","description_en":"","first_published":null,"fixed":{"7.3":"7.3.19","7.4":"7.4.17","8.0":"8.0.13","8.1":"8.1.9","8.2":"8.2.4"},"id":"CVE-2007-2138","introduced":{},"published":{},"score":null,"title":"A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.","url":"https://www.postgresql.org/support/security/CVE-2007-2138/","vector":""},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"A vulnerability involving insecure search_path settings allows unprivileged users to gain the SQL privileges of the owner of any SECURITY DEFINER function they are allowed to call. Securing such a function requires both a software update and changes to the function definition.","description":"","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"35b8b533823dc47803b728e306d60136ac0fb458309706bf42fe21f523894e06"},"locales":["en"],"fixes":[{"major":"7.3","fixed_version":"7.3.19","introduced":null,"published_date":null,"facts":{"fixed":"7.3.19","introduced":null,"published":null}},{"major":"7.4","fixed_version":"7.4.17","introduced":null,"published_date":null,"facts":{"fixed":"7.4.17","introduced":null,"published":null}},{"major":"8.0","fixed_version":"8.0.13","introduced":null,"published_date":null,"facts":{"fixed":"8.0.13","introduced":null,"published":null}},{"major":"8.1","fixed_version":"8.1.9","introduced":null,"published_date":null,"facts":{"fixed":"8.1.9","introduced":null,"published":null}},{"major":"8.2","fixed_version":"8.2.4","introduced":null,"published_date":null,"facts":{"fixed":"8.2.4","introduced":null,"published":null}}],"legacy":[]}
