CVE-2025-5690 - CVE House
Back to Database
Status published Medium CVE-2025-5690

Cursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic data

Vulnerability Description

PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules defined on a table and read the original data using a database cursor or the --insert option of pg_dump. This problem occurs only when dynamic masking is enabled, which is not the default setting. The problem is resolved in version 2.2.1

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5690

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The PostgreSQL Anonymizer project thanks Jukka Heiskanen for reporting this problem.

Affected Vendor

Affected Software

PostgreSQL Anonymizer
Vulnerable Versions:
1

Timeline

Official Publish: June 4th, 2025
Last Modified: June 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)