Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-mrww-27vc-gghv

больше 2 лет назад

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-27304

больше 2 лет назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-27304

больше 2 лет назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-27304

больше 2 лет назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2024-27304

около 2 лет назад

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-27304

больше 2 лет назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-01921

больше 2 лет назад

Уязвимость набора инструментов для работы с PostgreSQL pgx, связанная с непринятием мер по защите структуры SQL-запроса, позволяющая нарушителю выполнять произвольные SQL-запросы

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mrww-27vc-gghv

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-27304

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur ...

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-01921

Уязвимость набора инструментов для работы с PostgreSQL pgx, связанная с непринятием мер по защите структуры SQL-запроса, позволяющая нарушителю выполнять произвольные SQL-запросы

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу