GHSA-5c6q-f783-h888 – com.amazon.redshift:redshift-jdbc42
Package
Manager: maven
Name: com.amazon.redshift:redshift-jdbc42
Vulnerable Version: <0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-jc69-hjw2-fm86. This link is maintained to preserve external references. ## Original Description In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. This issue has been fixed in version 2.1.0.8.
Metadata
Created: 2022-09-30T00:00:20Z
Modified: 2024-10-07T20:58:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-5c6q-f783-h888/GHSA-5c6q-f783-h888.json
CWE IDs: ["CWE-704"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0