VDB
Sign up
LOW

GHSA-j88v-2chj-qfwx

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Quick fix

GHSA-j88v-2chj-qfwx — github.com/jackc/pgx/v5: upgrade to the fixed version with the command below.

go get github.com/jackc/pgx/v5@v5.9.2

Details

### Impact

SQL Injection can occur when:

1. The non-default simple protocol is used. 2. A dollar quoted string literal is used in the SQL query. 3. That string literal contains text that would be would be interpreted as a placeholder outside of a string literal. 4. The value of that placeholder is controllable by the attacker.

e.g.

```go attackValue := `$tag$; drop table canary; --` _, err = tx.Exec(ctx, `select $tag$ $1 $tag$, $1`, pgx.QueryExecModeSimpleProtocol, attackValue) ```

This is unlikely to occur outside of a contrived scenario.

### Patches

The problem is resolved in v5.9.2.

### Workarounds

Do not use the simple protocol to execute queries matching all the above conditions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/jackc/pgx/v5
Introduced in: 0Fixed in: 5.9.2
Fixgo get github.com/jackc/pgx/v5@v5.9.2
Go/github.com/jackc/pgx/v4
Introduced in: 0

No fixed version published yet for github.com/jackc/pgx/v4 (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/jackc/pgx
Introduced in: 0

No fixed version published yet for github.com/jackc/pgx (go modules). Pin to a known-safe version or switch to an alternative.

References