CVE-2012-1618
Unescaped parameters in the PostgreSQL JDBC driver
EPSS 2.9%
描述
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.
如何修補 CVE-2012-1618
要修補 CVE-2012-1618,請將受影響套件升級到下列已修補版本。
- —升級至 8.2 或更新版本
CVE-2012-1618 正在被利用嗎?
低 — EPSS 為 2.9%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 8.2