← volver
CVE-2025-5690mediumCWE-200

Cursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic data

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.5epss 0.3%
probabilidad de explotación
0.3%top 79% de las CVE
explotación observada
noninguna fuente lo reporta
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The problem is resolved in version 2.2.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N