CVE-2024-12744

CVSS 3.1 Score 8 of 10 (high)

Details

Published Dec 24, 2024
Updated: Dec 26, 2024
CWE ID 89

Summary

CVE-2024-12744 is a newly disclosed SQL injection vulnerability affecting the Amazon Redshift JDBC Driver version 2.1.0.31. Malicious users can exploit this issue by manipulating input to the getSchemas, getTables, or getColumns Metadata APIs, resulting in the elevation of privileges. To mitigate this risk, users are advised to upgrade to the driver version 2.1.0.32 or revert to the previously Patched version 2.1.0.30. This vulnerability could potentially allow attackers to gain unauthorized access to sensitive data or modify database configurations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share