GO-2024-2605
Dashboard / Vulnerabilities / GO-2024-2605
Summary: SQL injection in github.com/jackc/pgx/v4
Details: SQL injection is possible when the database uses the non-default simple protocol, a minus sign directly precedes a numeric placeholder followed by a string placeholder on the same line, and both parameter values are user-controlled.
References: https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p, https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df
Affected packages
Package
Name: github.com/jackc/pgx
Purl: pkg:golang/github.com/jackc/pgx
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
