NA

CVE-2022-41828

Published: 29/09/2022 Updated: 07/11/2022
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) prior to 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amazon amazon web services redshift java database connectivity driver

Github Repositories

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE) The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions The Driver provides access to Redshift from any Java application, application server, o