{"id":"CVE-2024-12745","aliases":["GHSA-8gc2-vq6m-rwjw","PYSEC-2026-1866"],"url":"https://o3.security/vulnerability/CVE-2024-12745","summary":"SQL Injection in the Amazon Redshift Python Connector affecting v2.1.4","details":"A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.","published":"2024-12-24T16:15:08.718Z","modified":"2026-08-08T03:48:01.411406406Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"redshift-connector","fixedVersion":"2.1.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/AWS-2024-015/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12745.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-8gc2-vq6m-rwjw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12745"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.5"},{"type":"PACKAGE","url":"https://github.com/aws/amazon-redshift-python-driver"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:01.411406406Z"}}