CVE-2024-12745: Amazon Redshift Python Connector vulnerable to SQL Injection
(updated )
A SQL injection in the Amazon Redshift Python Connector in version 2.1.4 allows a user to gain escalated privileges via schema injection in the get_schemas, get_tables, or get_columns Metadata APIs. Users should upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
References
- aws.amazon.com/security/security-bulletins/AWS-2024-015
- github.com/advisories/GHSA-8gc2-vq6m-rwjw
- github.com/aws/amazon-redshift-python-driver
- github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.5
- github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-8gc2-vq6m-rwjw
- nvd.nist.gov/vuln/detail/CVE-2024-12745
Code Behaviors & Features
Detect and mitigate CVE-2024-12745 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →