CVE-2024-2338 is a SQL injection vulnerability in PostgreSQL Anonymizer v1.2 that allows a table owner to escalate privileges to superuser when dynamic masking is enabled. The flaw stems from allowing complex expressions in security labels, which are then used verbatim to create masked views. This high-severity vulnerability (CVSS 7.5) requires a low-privileged user who owns a table and has dynamic masking enabled, with high impact on confidentiality, integrity, and availability. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:dalibo:anonymizer:1.2.0:*:*:*:*:postgresql:*:* | ||
>= 1, < 1.3.0CPE match | cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.