Security release CVE-2022-31197

Поиск
Список
Период
Сортировка
От Dave Cramer
Тема Security release CVE-2022-31197
Дата
Msg-id CADK3HH+zHr3NDN-GgyHTc38nbKPJ620pA9kR_nt0gq2JrCw8cw@mail.gmail.com
обсуждение исходный текст
Ответы Re: Security release CVE-2022-31197  (Sehrope Sarkuni <sehrope@jackdb.com>)
Список pgsql-jdbc
Greetings,

We have released 42.2.26 and 42.4.1 to address a security issue.

Previously, the column names for both key and data columns in the table were copied as-is into the generated SQL. This allowed a malicious table with column names that include statement terminator to be parsed and executed as multiple separate commands.

Thanks to Sho Kato https://github.com/kato-sho for finding and reporting the issue

Regards,

pgjdbc team

В списке pgsql-jdbc по дате отправления:

Предыдущее
От: Dave Cramer
Дата:
Сообщение: [pgjdbc/pgjdbc]
Следующее
От: Sehrope Sarkuni
Дата:
Сообщение: Re: Security release CVE-2022-31197