GHSA-x3wm-hffr-chwm
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
Quick fix
GHSA-x3wm-hffr-chwm — com.amazon.redshift:redshift-jdbc42: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.1.0.28</version> for com.amazon.redshift:redshift-jdbc42Details
### Impact
SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value.
There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected.
### Patch
This issue is patched in driver version 2.1.0.28.
### Workarounds
Do not use the connection property `preferQueryMode=simple`. (NOTE: If you do not explicitly specify a query mode, then you are using the default of extended query mode and are not affected by this issue.)
### References
Similar to finding in Postgres JDBC: https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56
If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.1.0.28# pom.xml: bump <version>2.1.0.28</version> for com.amazon.redshift:redshift-jdbc42References
- https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm[WEB]
- https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32888[ADVISORY]
- https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319[WEB]
- https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339[WEB]
- https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d[WEB]
- https://github.com/aws/amazon-redshift-jdbc-driver[PACKAGE]
- https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw[WEB]