Security release CVE-2022-31197

Поиск
Список
Период
Сортировка
От Dave Cramer
Тема Security release CVE-2022-31197
Дата
Msg-id CADK3HH+zHr3NDN-GgyHTc38nbKPJ620pA9kR_nt0gq2JrCw8cw@mail.gmail.com
обсуждение исходный текст
Ответы Re: Security release CVE-2022-31197
Список pgsql-jdbc
Greetings,

We have released 42.2.26 and 42.4.1 to address a security issue.

Previously, the column names for both key and data columns in the table were copied as-is into the generated SQL. This allowed a malicious table with column names that include statement terminator to be parsed and executed as multiple separate commands.

Thanks to Sho Kato https://github.com/kato-sho for finding and reporting the issue

Regards,

pgjdbc team

В списке pgsql-jdbc по дате отправления: