Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13455

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:*
Версия до 3.1.2 (включая)

EPSS

Процентиль: 2%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-328

Связанные уязвимости

CVSS3: 4.3
redhat
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

CVSS3: 4.3
github
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

EPSS

Процентиль: 2%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-328