No advisories yet.
Solution
No solution given by the vendor.
Workaround
Remove the rules import functions named `anon.import_roles_rules()` and `anon.import_database_rules()`. They are user-facing functions with no internal dependencies.
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/643 |
|
Thu, 11 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dalibo
Dalibo postgresql Anonymizer |
|
| Vendors & Products |
Dalibo
Dalibo postgresql Anonymizer |
Thu, 11 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions | |
| Title | PostgreSQL Anonymizer: SQL injection in the rules import functions | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-06-11T18:34:38.312Z
Reserved: 2026-06-10T21:28:53.029Z
Link: CVE-2026-11945
Updated: 2026-06-11T18:34:34.480Z
Status : Awaiting Analysis
Published: 2026-06-11T17:16:31.837
Modified: 2026-06-11T20:56:29.653
Link: CVE-2026-11945
No data.
OpenCVE Enrichment
Updated: 2026-06-11T20:30:28Z