PT-2024-24941 · Amazon · Amazon Redshift Jdbc Driver

Paul-Gerste-Sonarsource

·

Published

2024-02-21

·

Updated

2025-06-12

·

CVE-2024-32888

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon Redshift JDBC Driver versions prior to 2.1.0.28
Description The issue allows for SQL injection when using the non-default connection property preferQueryMode=simple in combination with application code that has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. The preferQueryMode property is not a supported parameter in the Redshift JDBC driver and is inherited code from the Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected.
Recommendations For Amazon Redshift JDBC Driver versions prior to 2.1.0.28, do not use the connection property preferQueryMode=simple to mitigate the issue. Upgrade to version 2.1.0.28 or later to patch the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-32888
GHSA-24RP-Q3W6-VC56
GHSA-X3WM-HFFR-CHWM

Affected Products

Amazon Redshift Jdbc Driver