Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c6q-f783-h888

Опубликовано: 30 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jc69-hjw2-fm86. This link is maintained to preserve external references.

Original Description

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. This issue has been fixed in version 2.1.0.8.

Пакеты

Наименование

com.amazon.redshift:redshift-jdbc42

maven
Затронутые версииВерсия исправления

< 2.1.0.8

2.1.0.8

8.1 High

CVSS3

Дефекты

CWE-704

8.1 High

CVSS3

Дефекты

CWE-704