High severity8.0NVD Advisory· Published Dec 24, 2024· Updated Jun 17, 2026
CVE-2024-12745
CVE-2024-12745
Description
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
redshift_connectorPyPI | >= 2.1.4, < 2.1.5 | 2.1.5 |
Affected products
9- ghsa-coords7 versionspkg:pypi/redshift_connectorpkg:apk/chainguard/airflow-bitnami-compatpkg:apk/wolfi/airflow-bitnami-compatpkg:apk/wolfi/airflowpkg:apk/chainguard/airflow-compatpkg:apk/wolfi/airflow-compatpkg:apk/chainguard/airflow
>= 2.1.4, < 2.1.5+ 6 more
- (no CPE)range: >= 2.1.4, < 2.1.5
- (no CPE)range: < 2.10.4-r2
- (no CPE)range: < 2.10.4-r2
- (no CPE)range: < 2.10.4-r2
- (no CPE)range: < 2.10.4-r2
- (no CPE)range: < 2.10.4-r2
- (no CPE)range: < 2.10.4-r2
- Range: 2.1.4
- cpe:2.3:a:amazon:redshift_connector:2.1.4:*:*:*:*:python:*:*
Patches
Vulnerability mechanics
References
6- aws.amazon.com/security/security-bulletins/AWS-2024-015/nvdVendor Advisory
- github.com/advisories/GHSA-8gc2-vq6m-rwjwghsaADVISORY
- github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-8gc2-vq6m-rwjwnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-12745ghsaADVISORY
- aws.amazon.com/security/security-bulletins/AWS-2024-015ghsaWEB
- github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.5nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.