Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8ch8-93q8-mhm3

Опубликовано: 30 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

EPSS

Процентиль: 2%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-328

Связанные уязвимости

CVSS3: 4.3
redhat
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

CVSS3: 4.3
nvd
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

EPSS

Процентиль: 2%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-328