PostgreSQL Vulnerability Security Update Advisory

Overview

 

An update has been made available to fix vulnerabilities in the PostgreSQL JDBC driver, pgjdbc. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

  • Prior to pGJDBC 42.2.28  versions
  • pgjdbc Versions greater than 42.2.28, 42.2.28.jre7 but less than 42.3.9
  • pgjdbc Versions greater than 42.3.9 but less than 42.4.4
  • pgjdbc Versions greater than 42.4.4 but less than 42.5.5
  • pgjdbc Versions greater than 42.5.5 but less than 42.7.2

 

Resolved Vulnerabilities

 

SQL Injection vulnerability when using PreferQueryMode=SIMPLE in the PostgreSQL JDBC driver, pgjdbc (CVE-2024-1597)

 

Vulnerability Patches

 

Vulnerability patches were made available in the February 21, 2024 update. Please update to the latest vulnerability patch version according to the reference site.

  • pGJDBC 42.2.28, 42.2.28.jre7 versions
  • pGJDBC 42.3.9 version
  • pgjdbc 42.4.4 version
  • pgjdbc 42.5.5 version
  • pgjdbc 42.6.1 version
  • pgjdbc 42.7.2 version

 

Referenced Sites

 

[1] CVE-2024-1597 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-1597
[2] SQL Injection via line comment generation
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56