{"id":"GHSA-x3wm-hffr-chwm","summary":"Amazon JDBC Driver for Redshift SQL Injection via line comment generation","details":"### Impact\n\nSQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value.\n\nThere is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected.\n\n### Patch\n\nThis issue is patched in driver version 2.1.0.28.\n\n### Workarounds\n\nDo not use the connection property `preferQueryMode=simple`. (NOTE: If you do not explicitly specify a query mode, then you are using the default of extended query mode and are not affected by this issue.)\n\n### References\n\nSimilar to finding in Postgres JDBC: https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","aliases":["CVE-2024-32888"],"modified":"2026-07-17T20:58:35.396867460Z","published":"2024-05-15T17:10:49Z","related":["CVE-2024-32888"],"database_specific":{"cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-05-15T17:10:49Z","nvd_published_at":"2024-05-15T03:15:12Z"},"references":[{"type":"WEB","url":"https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm"},{"type":"WEB","url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32888"},{"type":"WEB","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319"},{"type":"WEB","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339"},{"type":"WEB","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d"},{"type":"PACKAGE","url":"https://github.com/aws/amazon-redshift-jdbc-driver"},{"type":"WEB","url":"https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw"}],"affected":[{"package":{"name":"com.amazon.redshift:redshift-jdbc42","ecosystem":"Maven","purl":"pkg:maven/com.amazon.redshift/redshift-jdbc42"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0.28"}]}],"versions":["2.0.0.3","2.0.0.4","2.0.0.5","2.0.0.6","2.0.0.7","2.1.0.1","2.1.0.10","2.1.0.11","2.1.0.12","2.1.0.13","2.1.0.14","2.1.0.15","2.1.0.16","2.1.0.17","2.1.0.18","2.1.0.19","2.1.0.2","2.1.0.20","2.1.0.21","2.1.0.22","2.1.0.23","2.1.0.24","2.1.0.25","2.1.0.26","2.1.0.27","2.1.0.3","2.1.0.4","2.1.0.5","2.1.0.6","2.1.0.7","2.1.0.8","2.1.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-x3wm-hffr-chwm/GHSA-x3wm-hffr-chwm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}