216.73.216.233

CVE-2024-12744

· Published 24/12/2024 17:15 · Modified 26/12/2024 15:15

Labels: CVE-2024-12744 2024-12-24CVE-2024-12744CWE-89ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
24/12/2024 17:15
Modified
26/12/2024 15:15
Author
Creator
CVSS
8.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

References