Set User Project maintains a focused utility for privilege escalation and user account management, with reported vulnerabilities centered on improper handling of privilege delegation and access-control boundaries. The durable signal reflects the sensitive nature of privilege-management tools, where flaws in authorization logic can directly compromise system security; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Set User Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41558CRITICAL The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config. | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-38140CRITICAL The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user(). | Aug 10, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Set User Project.
Media articles that mention a CVE ID that affects a product developed by Set User Project — matched by CVE ID, not by vendor name.