First published: Thu Sep 29 2022(Updated: )
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Amazon Web Services Redshift Java Database Connectivity Driver | <2.1.0.8 |
https://github.com/aws/amazon-redshift-jdbc-driver/commit/40b143b4698faf90c788ffa89f2d4d8d2ad068b5
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-41828.
The severity of CVE-2022-41828 is high with a score of 8.1.
Amazon AWS Redshift JDBC Driver before version 2.1.0.8 is affected by CVE-2022-41828.
CVE-2022-41828 is a vulnerability in the Amazon AWS Redshift JDBC Driver where the Object Factory does not check the class type when instantiating an object from a class name.
To fix CVE-2022-41828, update the Amazon AWS Redshift JDBC Driver to version 2.1.0.8 or later.