Bug 2266523 (CVE-2024-1597)
Summary: | CVE-2024-1597 pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Avinash Hanwate <ahanwate> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | adupliak, aileenc, anstephe, asoldano, avibelli, bbaranow, bbuckingham, bcourt, bgeorges, bmaxwell, boliveir, brian.stansberry, btarraso, cdewolf, chazlett, clement.escoffier, cmiranda, dandread, darran.lofthouse, dhanak, dkreling, dosoudil, dpalmer, drichtar, dsimansk, ecerquei, ehelms, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, gsmet, ibek, ivassile, iweiss, janstey, jmartisk, jnethert, jpoth, jrokos, jsherril, kingland, kverlaen, lgao, lthon, lzap, matzew, max.andersen, mhulan, michal.skrivanek, mnovotny, mosmerov, mperina, msochure, mstefank, msvehla, mulliken, nmoumoul, nwallace, olubyans, orabin, pantinor, pcongius, pcreech, pdelbell, pdrozd, peholase, pgallagh, pierdipi, pjindal, pmackay, probinso, pskopek, rchan, rguimara, rhuss, rowaters, rruss, rstancel, rsvoboda, saroy, sausingh, sbiarozk, smaestri, sthorger, tcunning, tom.jenkinson, tqvarnst, yfang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | PostgreSQL JDBC Driver 42.7.2, PostgreSQL JDBC Driver 42.6.1,PostgreSQL JDBC Driver 42.5.5, PostgreSQL JDBC Driver 42.4.4, PostgreSQL JDBC Driver 42.3.9, PostgreSQL JDBC Driver 42.2.28, PostgreSQL JDBC Driver 42.2.28.jre7 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the PostgreSQL JDBC Driver. A SQL injection is possible when using the non-default connection property preferQueryMode=simple in combination with application code that has a vulnerable SQL that negates a parameter value.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2266524, 2266525, 2270746 | ||
Bug Blocks: | 2266526 |
Description
Avinash Hanwate
2024-02-28 04:38:15 UTC
Created postgresql-jdbc tracking bugs for this issue: Affects: fedora-all [bug 2266524] Commits: https://github.com/pgjdbc/pgjdbc/commit/93b0fcb2711d9c1e3a2a03134369738a02a58b40 (REL42.7.2) https://github.com/pgjdbc/pgjdbc/commit/06abfb78a627277a580d4df825f210e96a4e14ee (REL42.7.2) https://github.com/pgjdbc/pgjdbc/commit/1b1d6b53eca90409af0069d5327d4fdf8d40a255 (REL42.5.5) https://github.com/pgjdbc/pgjdbc/commit/475e3e2af3033c666fc1c0015159b35455118ae5 (REL42.5.5) https://github.com/pgjdbc/pgjdbc/commit/b9b3777671c8a5cc580e1985f61337d39d47c730 (REL42.2.28) https://github.com/pgjdbc/pgjdbc/commit/990d63f6be401ab40de5eb303a75924c9e71903c (REL42.2.28) This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1435 https://access.redhat.com/errata/RHSA-2024:1435 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1436 https://access.redhat.com/errata/RHSA-2024:1436 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:1649 https://access.redhat.com/errata/RHSA-2024:1649 This issue has been addressed in the following products: Red Hat build of Quarkus 3.2.11 Via RHSA-2024:1662 https://access.redhat.com/errata/RHSA-2024:1662 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2024:1686 https://access.redhat.com/errata/RHSA-2024:1686 This issue has been addressed in the following products: Red Hat build of Quarkus 2.13.9.SP2 Via RHSA-2024:1797 https://access.redhat.com/errata/RHSA-2024:1797 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:1999 https://access.redhat.com/errata/RHSA-2024:1999 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2024:2624 https://access.redhat.com/errata/RHSA-2024:2624 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:3313 https://access.redhat.com/errata/RHSA-2024:3313 This issue has been addressed in the following products: RHOSS-1.33-RHEL-8 Via RHSA-2024:4057 https://access.redhat.com/errata/RHSA-2024:4057 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:4375 https://access.redhat.com/errata/RHSA-2024:4375 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:4402 https://access.redhat.com/errata/RHSA-2024:4402 This issue has been addressed in the following products: Red Hat build of Apache Camel 4.4.1 for Spring Boot Via RHSA-2024:4884 https://access.redhat.com/errata/RHSA-2024:4884 This issue has been addressed in the following products: RHINT Camel-K 1.10.7 Via RHSA-2024:5056 https://access.redhat.com/errata/RHSA-2024:5056 |