PostgreSQL Anonymizer 存在一个漏洞,允许未获得特权的脱敏用户反复调用 anon.hash() 函数,收集(种子,哈希输出)对,从而执行离线暴力破解攻击并推断出盐值。当调用被放置在子查询内部时,脱敏角色可以执行受限函数。该问题已在 PostgreSQL Anonymizer 3.2.3 及更高版本中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DALIBO | PostgreSQL Anonymizer | 1< 3.2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DALIBO | PostgreSQL Anonymizer | 1 ~ 3.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet