DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8953-rp52-8xp5

Published

Last updated

https://images.chainguard.dev/security/CGA-8953-rp52-8xp5
Package

k3s

Latest Update
Fixed
Fixed Version

1.29.2-r3

Aliases
  • CVE-2024-27304
  • GHSA-mrww-27vc-gghv

Severity

9.8

Critical

CVSS V3

Summary

pgx SQL Injection via Protocol Message Size Overflow

Description

Impact

SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.

Patches

The problem is resolved in v4.18.2 and v5.5.4.

Workarounds

Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images