A vulnerability in PostgreSQL Anonymizer allows unprivileged masked users to perform an offline brute-force attack to deduce the salt by repeatedly calling the anon.hash() function. The issue is resolved in PostgreSQL Anonymizer 3.2.3 and later versions. This vulnerability impacts systems using PostgreSQL Anonymizer, particularly those with unprivileged users, requiring defenders to assess exposure and pr [truncated]
PostgreSQL Anonymizer vulnerability allows unprivileged masked users to execute arbitrary code with elevated privileges by abusing operators, domain casts, or view subqueries with untrusted expressions. This issue arises when these objects are evaluated in the context of the extension's masking mechanisms. The vulnerability is addressed in PostgreSQL Anonymizer version 3.1.4 and later. Affected deployment [truncated]
A vulnerability in PostgreSQL Anonymizer allows a user to gain superuser privileges. By creating a JSON document and placing malicious code inside a particular key-value pair, an attacker can exploit this issue. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. This vulnerability has a CVSS score of 6.4 and is clas [truncated]
A privilege escalation vulnerability in PostgreSQL Anonymizer allows authenticated database users to execute arbitrary code with superuser privileges when a superuser invokes the k-anonymity function on a maliciously crafted table. The attack vector involves embedding malicious code within column identifiers, which are then executed during function processing. The vulnerability is more readily exploitable [truncated]