CVE-2024-12745

Published
View on NVD ↗
CVSS v3
8
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.

Redshift Python Connector. It supports Python Database API Specification v2.0.
GitHubGitHub
219