Логотип exploitDog
bind:CVE-2024-2339
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2339

Количество 3

Количество 3

nvd логотип

CVE-2024-2339

почти 2 года назад

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-fvc5-hrmq-8hx4

почти 2 года назад

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.

CVSS3: 8
EPSS: Низкий
fstec логотип

BDU:2024-01984

почти 2 года назад

Уязвимость опции restrict_to_trusted_schemas расширения PostgreSQL анонимизации данных в базе данных PostgreSQL Anonymizer, позволяющая нарушителю повысить свои привилегии до уровня superuser

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-2339

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.

CVSS3: 8
0%
Низкий
почти 2 года назад
github логотип
GHSA-fvc5-hrmq-8hx4

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function for a column and place malicious code in that function. When a privileged user applies the masking rules using the static masking or the anonymous dump method, the malicious code is executed and can grant escalated privileges to the malicious user. PostgreSQL Anonymizer v1.2 does provide a protection against this risk with the restrict_to_trusted_schemas option, but that protection is incomplete. Users that don't own a table, especially masked users cannot exploit this vulnerability. The problem is resolved in v1.3.

CVSS3: 8
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-01984

Уязвимость опции restrict_to_trusted_schemas расширения PostgreSQL анонимизации данных в базе данных PostgreSQL Anonymizer, позволяющая нарушителю повысить свои привилегии до уровня superuser

CVSS3: 8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу