SQL Injection Affecting dalibo/postgresql_anonymizer package, versions [,1.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.46% (37th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-DALIBOPOSTGRESQLANONYMIZER-6421111
  • published11 Mar 2024
  • disclosed8 Mar 2024
  • creditUnknown

Introduced: 8 Mar 2024

CVE-2024-2338  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade dalibo/postgresql_anonymizer to version 1.3.0 or higher.

Overview

Affected versions of this package are vulnerable to SQL Injection via the implementation of dynamic masking, which allows complex expressions to be provided as a value. These expressions are later used to create masked views, leading to an exploit where a user who owns a table can elevate their privileges to superuser after the label is created.

Note:

This issue does not affect users who do not own a table, particularly masked users.

Workaround

This vulnerability can be mitigated by disabling dynamic masking

References

CVSS Base Scores

version 3.1