CVE-2024-44906: SQL Injection
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go.
Other sources
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44906?
CVE-2024-44906 has been classified as a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2024-44906?
To fix CVE-2024-44906, update the uptrace pgdriver to version 1.2.15 or later.
What does the CVE-2024-44906 vulnerability exploit?
CVE-2024-44906 exploits a SQL injection vulnerability found in the appendArg function within /pgdriver/format.go.
Which versions of the uptrace pgdriver are affected by CVE-2024-44906?
Versions of the uptrace pgdriver up to and including 1.2.14 are affected by CVE-2024-44906.
What are the potential impacts of CVE-2024-44906?
The potential impacts of CVE-2024-44906 include unauthorized data access and manipulation due to SQL injection.