Логотип exploitDog
bind:CVE-2024-27304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27304

Количество 7

Количество 7

ubuntu логотип

CVE-2024-27304

почти 2 года назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-27304

почти 2 года назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-27304

почти 2 года назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2024-27304

больше 1 года назад

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-27304

почти 2 года назад

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mrww-27vc-gghv

почти 2 года назад

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-01921

почти 2 года назад

Уязвимость набора инструментов для работы с PostgreSQL pgx, связанная с непринятием мер по защите структуры SQL-запроса, позволяющая нарушителю выполнять произвольные SQL-запросы

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
2%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 8.1
2%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

CVSS3: 9.8
2%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-27304

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-27304

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur ...

CVSS3: 9.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-mrww-27vc-gghv

pgx SQL Injection via Protocol Message Size Overflow

CVSS3: 9.8
2%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-01921

Уязвимость набора инструментов для работы с PostgreSQL pgx, связанная с непринятием мер по защите структуры SQL-запроса, позволяющая нарушителю выполнять произвольные SQL-запросы

CVSS3: 9.8
2%
Низкий
почти 2 года назад

Уязвимостей на страницу