Advisories ยป MGASA-2024-0120

Updated postgresql-jdbc packages fix security vulnerability

Publication date: 11 Apr 2024
Modification date: 11 Apr 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-1597

Description

pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if
using PreferQueryMode=SIMPLE. Note this is not the default. In the
default mode there is no vulnerability. A placeholder for a numeric
value must be immediately preceded by a minus. There must be a second
placeholder for a string value after the first placeholder; both must be
on the same line. By constructing a matching string payload, the
attacker can inject SQL to alter the query,bypassing the protections
that parameterized queries bring against SQL Injection attacks.
(CVE-2024-1597)
                

References

SRPMS

9/core