CVE-2024-32888
Last modified
CVE-2024-32888 is a critical-severity vulnerability rated 10/10 on the CVSS scale. The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. EPSS estimates a 0.78% chance of exploitation in the next 30 days.
Description
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-32888?
How severe is CVE-2024-32888?
How do I fix CVE-2024-32888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-32881Danswer is the AI Assistant connected to company's docs, app…9.8
- CVE-2024-32882Wagtail is an open source content management system built on…2.7
- CVE-2024-32883MCUboot is a secure bootloader for 32-bits microcontrollers.…7.7
- CVE-2024-32884gitoxide is a pure Rust implementation of Git. `gix-transpor…6.4
- CVE-2024-32886Vitess is a database clustering system for horizontal scalin…4.9
- CVE-2024-32887Sidekiq is simple, efficient background processing for Ruby.…5.5
- CVE-2024-3289When installing Nessus to a directory outside of the default…7.8
- CVE-2024-32890librespeed/speedtest is an open source, self-hosted speed te…6.1
- CVE-2024-32891In sec_media_unprotect of media.c, there is a possible memor…7
- CVE-2024-32892In handle_init of goodix/main/main.c, there is a possible me…7.8
- CVE-2024-32893In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possib…5.5
- CVE-2024-32894In bc_get_converted_received_bearer of bc_utilities.c, there…7.5
Are you affected by CVE-2024-32888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
