Dalibo

Postgresql Anonymizer

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 25.09.2026 15:40:45
  • Zuletzt bearbeitet 29.09.2026 21:27:41

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can ru...

  • EPSS 0.19%
  • Veröffentlicht 06.09.2026 15:25:41
  • Zuletzt bearbeitet 09.09.2026 05:18:19

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

  • EPSS 0.19%
  • Veröffentlicht 06.09.2026 15:25:36
  • Zuletzt bearbeitet 09.09.2026 05:17:20

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import...

  • EPSS 0.36%
  • Veröffentlicht 06.09.2026 15:25:32
  • Zuletzt bearbeitet 09.09.2026 05:17:19

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of...

  • EPSS 0.12%
  • Veröffentlicht 30.06.2026 15:19:57
  • Zuletzt bearbeitet 06.07.2026 20:23:09

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resol...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 11.06.2026 15:53:24
  • Zuletzt bearbeitet 16.06.2026 15:16:55

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles...