Skip to content

Conversation

@lesiak
Copy link

@lesiak lesiak commented Mar 29, 2024

Fixes:

  • CVE-2024-1597 [Critical] SQL Injection via line comment generation
  • CVE-2022-31197 [High] SQL Injection in ResultSet.refreshRow() with malicious column names
  • CVE-2022-41946 [Medium] TemporaryFolder on unix-like systems does not limit access to created files

Fixes:
- CVE-2024-1597 [Critical] SQL Injection via line comment generation
- CVE-2022-31197 [High]  SQL Injection in ResultSet.refreshRow() with malicious column names
- CVE-2022-41946 [Medium] TemporaryFolder on unix-like systems does not limit access to created files
@lesiak lesiak force-pushed the postgresql-driver-upgrade branch from 65cb71e to 93ebb2a Compare March 29, 2024 07:51
@jakepearson
Copy link

Would it be possible to accept this PR? I (and my security team) would be very grateful. 😄

@tomix26
Copy link
Collaborator

tomix26 commented Apr 8, 2024

@lesiak Thank you for another pull request 👍

@tomix26 tomix26 merged commit e4e5726 into zonkyio:master Apr 8, 2024
@tomix26
Copy link
Collaborator

tomix26 commented Apr 8, 2024

@jakepearson Yep, of course, I'll try to release the next version soon 🙂

@jakepearson
Copy link

Thanks a bunch for the release and the fantastic library!

@tomix26 tomix26 added this to the 2.1.0 milestone Nov 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants