So, the bug requires that the attacker can execute pg_dump to compromise the database?
So, they need to have access to the database already, and to pg_dump, presumably on the host?
Why does this have a severity of 8.8?
Why are you linking to some random site and not the postgresql announcement here: