PostgreSQL Vulnerability Security Update Advisory
Overview
An update has been made available to fix vulnerabilities in the PostgreSQL JDBC driver, pgjdbc. Users of affected versions are advised to update to the latest version.
Affected Products
- Prior to pGJDBC 42.2.28 versions
- pgjdbc Versions greater than 42.2.28, 42.2.28.jre7 but less than 42.3.9
- pgjdbc Versions greater than 42.3.9 but less than 42.4.4
- pgjdbc Versions greater than 42.4.4 but less than 42.5.5
- pgjdbc Versions greater than 42.5.5 but less than 42.7.2
Resolved Vulnerabilities
SQL Injection vulnerability when using PreferQueryMode=SIMPLE in the PostgreSQL JDBC driver, pgjdbc (CVE-2024-1597)
Vulnerability Patches
Vulnerability patches were made available in the February 21, 2024 update. Please update to the latest vulnerability patch version according to the reference site.
- pGJDBC 42.2.28, 42.2.28.jre7 versions
- pGJDBC 42.3.9 version
- pgjdbc 42.4.4 version
- pgjdbc 42.5.5 version
- pgjdbc 42.6.1 version
- pgjdbc 42.7.2 version
Referenced Sites
[1] CVE-2024-1597 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-1597
[2] SQL Injection via line comment generation
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56