PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1, < 3.1.1CPE match | cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:* | ||
< 3.1.1CPE matchmatch criteria | cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.