{"id":"CVE-2024-12744","aliases":["GHSA-8596-2jgr-ppj7"],"url":"https://o3.security/vulnerability/CVE-2024-12744","summary":"SQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31","details":"A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.","published":"2024-12-24T16:12:51.304Z","modified":"2026-08-08T03:48:00.997235015Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.amazon.redshift:redshift-jdbc42","fixedVersion":"2.1.0.32"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/AWS-2024-015/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12744.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-8596-2jgr-ppj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12744"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/releases/tag/v2.1.0.32"},{"type":"PACKAGE","url":"https://github.com/aws/amazon-redshift-jdbc-driver"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:00.997235015Z"}}