rpm package
almalinux/postgresql-jdbc
pkg:rpm/almalinux/postgresql-jdbc
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-1597 | — | < 42.2.14-3.el8_9 | 42.2.14-3.el8_9 | Feb 19, 2024 | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeh | ||
| CVE-2022-41946 | — | < 42.2.27-1.el9 | 42.2.27-1.el9 | Nov 23, 2022 | pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will crea | ||
| CVE-2022-31197 | — | < 42.2.18-6.el9_1 | 42.2.18-6.el9_1 | Aug 3, 2022 | PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious c | ||
| CVE-2020-13692 | — | < 42.2.3-3.el8_2 | 42.2.3-3.el8_2 | Jun 4, 2020 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
- CVE-2024-1597Feb 19, 2024affected < 42.2.14-3.el8_9fixed 42.2.14-3.el8_9
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeh
- CVE-2022-41946Nov 23, 2022affected < 42.2.27-1.el9fixed 42.2.27-1.el9
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will crea
- CVE-2022-31197Aug 3, 2022affected < 42.2.18-6.el9_1fixed 42.2.18-6.el9_1
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious c
- CVE-2020-13692Jun 4, 2020affected < 42.2.3-3.el8_2fixed 42.2.3-3.el8_2
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.