{"id":"CVE-2022-41828","aliases":["GHSA-jc69-hjw2-fm86"],"url":"https://o3.security/vulnerability/CVE-2022-41828","summary":"com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution","details":"In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.","published":"2022-09-29T00:00:00Z","modified":"2026-08-12T03:51:32.832002419Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"com.amazon.redshift:redshift-jdbc42","fixedVersion":"2.1.0.8"}],"fix":{"url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/40b143b4698faf90c788ffa89f2d4d8d2ad068b5","label":"aws/amazon-redshift-jdbc-driver@40b143b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41828.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-jc69-hjw2-fm86"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41828"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/40b143b4698faf90c788ffa89f2d4d8d2ad068b5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.832002419Z"}}