Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13455

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 4.3

Описание

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

A flaw was found in PostgreSQL Anonymizer. Unprivileged masked users can repeatedly call the anon.hash() function to collect seed and hash output pairs. This allows an attacker to perform an offline brute-force attack to deduce the salt, potentially leading to information disclosure.

Отчет

PostgreSQL Anonymizer is not shipped in any Red Hat product. It is available in Fedora and EPEL as a community package.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-916
https://bugzilla.redhat.com/show_bug.cgi?id=2495009postgresql_anonymizer: PostgreSQL Anonymizer: Information Disclosure via brute-force attack on hash function

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

CVSS3: 4.3
github
около 2 месяцев назад

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

4.3 Medium

CVSS3