CVE-2024-12744

HIGH

Amazon Redshift JDBC Driver 2.1.0.31 - SQL Injection via Metadata API

Title source: llm
STIX 2.1

Description

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.

Scores

CVSS v3 8.0
EPSS 0.0076
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
amazon/amazon_web_services_redshift_java_database_connectivity_driver 2.1.0.31
com.amazon.redshift/redshift-jdbc42 2.1.0.31 - 2.1.0.32Maven
Published Dec 24, 2024
Tracked Since Feb 18, 2026