DirectorySecurity Advisories
Sign In
Security Advisories

CGA-rqqc-qwmr-qw72

Published

Last updated

https://images.chainguard.dev/security/CGA-rqqc-qwmr-qw72
Package

vault-fips-1.14

Latest Update
Affected
Aliases
  • CVE-2024-27304
  • GHSA-mrww-27vc-gghv

Severity

9.8

Critical

CVSS V3

Summary

pgx SQL Injection via Protocol Message Size Overflow

Description

Impact

SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.

Patches

The problem is resolved in v4.18.2 and v5.5.4.

Workarounds

Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images