CVE-2024-27304
Last modified
CVE-2024-27304 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jackc | Pgproto3 | < 2.3.3 |
| Jackc | Pgx | < 4.18.2 |
| Jackc | Pgx | >= 5.0.0, < 5.5.4 |
References
- https://www.youtube.com/watch?v=Tfg1B8u1yvEPress/Media Coverage
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-27304?
How severe is CVE-2024-27304?
How do I fix CVE-2024-27304?
Are you affected by CVE-2024-27304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
