SQL injection in PostgreSQL driver and toolkit for Go - CVE-2024-27304
Published: March 26, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling overly large queries that exceed 4 GB in size. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Agent
Dell EMC OpenManage Enterprise Modular
IBM Cloud Pak for Watson AIOps
Red Hat Advanced Cluster Security for Kubernetes
IBM Observability with Instana
Fedora
caddy
How to mitigate CVE-2024-27304
Agent - update to 0.40.4
Red Hat Advanced Cluster Security for Kubernetes - update to 4.3.5
IBM Observability with Instana - update to 273
caddy - update to 2.8.4-1.fc41
Dell EMC OpenManage Enterprise Modular - update to 2.20.20
IBM Cloud Pak for Watson AIOps - update to 4.6.0
External References
- https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv
- https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8
- https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007
- https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4
- https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8
- https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df
Related Security Bulletins
- Multiple vulnerabilities in PostgreSQL driver and toolkit for Go
- SQL injection in pgproto3
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Agent
- SQL injection in IBM Instana Observability
- Fedora 41 update for caddy
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell OpenManage Enterprise Modular