Electric Electric是Electric公司的一个 Postgres 同步引擎。 Electric 1.6.10及之前版本存在侧信道信息泄露漏洞,该漏洞源于允许攻击者通过特制subset where子句条件推断被排除列的值,通过观察shape响应中subset where条件是否匹配行来推断敏感字段数据,绕过基于列的访问限制,导致信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ElectricSQL | Electric Postgres Sync | ≤ 1.6.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ElectricSQL | Electric Postgres Sync | 0 ~ 1.6.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet