In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:8 postgresql:10/postgresql-test to version 0:10.21-2.module+el8.4.0+15341+25c9f2fe or higher.
This issue was patched in RHSA-2022:4854.
Note: Versions mentioned in the description apply only to the upstream postgresql:10/postgresql-test package and not the postgresql:10/postgresql-test package as distributed by RHEL.
See How to fix? for RHEL:8 relevant fixed versions and status.
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.