{"id":"CVE-2024-32888","aliases":["GHSA-x3wm-hffr-chwm"],"url":"https://o3.security/vulnerability/CVE-2024-32888","summary":"Amazon JDBC Driver for Redshift SQL Injection via line comment generation","details":"### Impact\n\nSQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value.\n\nThere is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected.\n\n### Patch\n\nThis issue is patched in driver version 2.1.0.28.\n\n### Workarounds\n\nDo not use the connection property `preferQueryMode=simple`. (NOTE: If you do not explicitly specify a query mode, then you are using the default of extended query mode and are not affected by this issue.)\n\n### References\n\nSimilar to finding in Postgres JDBC: https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56\n\nIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.","published":"2024-05-15T02:16:47.796Z","modified":"2026-08-12T15:13:00.549770Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.00778,"percentile":0.5274,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.amazon.redshift:redshift-jdbc42","fixedVersion":"2.1.0.28"}],"fix":{"url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319","label":"aws/amazon-redshift-jdbc-driver@0d354a5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32888.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm"},{"type":"ADVISORY","url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32888"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d"},{"type":"ARTICLE","url":"https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw/"},{"type":"PACKAGE","url":"https://github.com/aws/amazon-redshift-jdbc-driver"},{"type":"WEB","url":"https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:13:00.549770Z"}}