Advisories for Maven/Com.amazon.redshift/Redshift-Jdbc42 package

2024

Amazon JDBC Driver for Redshift SQL Injection via line comment generation

SQL injection is possible when using the non-default connection property preferQueryMode=simple in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that preferQueryMode is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this …

2022