QID 997410
Date Published: 2024-02-23
QID 997410: Java (Maven) Security Update for org.postgresql:postgresql (GHSA-24rp-q3w6-vc56)
SQL injection is possible when using the non-default connection property preferQueryMode=simple in combination with application code that has a vulnerable SQL that negates a parameter value.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-24rp-q3w6-vc56 for updates and patch information.
Vendor References
- GHSA-24rp-q3w6-vc56 -
github.com/advisories/GHSA-24rp-q3w6-vc56
CVEs related to QID 997410
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-24rp-q3w6-vc56 | org.postgresql:postgresql |
|