Cursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic data
Vulnerability Description
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The problem is resolved in version 2.2.1
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5690
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- The PostgreSQL Anonymizer project thanks Jukka Heiskanen for reporting this problem.
Affected Vendor
DALIBO
View all reports →