Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade postgresql driver to 42.7.3 #130

Merged
merged 1 commit into from
Apr 8, 2024

Conversation

lesiak
Copy link

@lesiak lesiak commented Mar 29, 2024

Fixes:

  • CVE-2024-1597 [Critical] SQL Injection via line comment generation
  • CVE-2022-31197 [High] SQL Injection in ResultSet.refreshRow() with malicious column names
  • CVE-2022-41946 [Medium] TemporaryFolder on unix-like systems does not limit access to created files

Fixes:
- CVE-2024-1597 [Critical] SQL Injection via line comment generation
- CVE-2022-31197 [High]  SQL Injection in ResultSet.refreshRow() with malicious column names
- CVE-2022-41946 [Medium] TemporaryFolder on unix-like systems does not limit access to created files
@jakepearson
Copy link

Would it be possible to accept this PR? I (and my security team) would be very grateful. 😄

@tomix26
Copy link
Collaborator

tomix26 commented Apr 8, 2024

@lesiak Thank you for another pull request 👍

@tomix26 tomix26 merged commit e4e5726 into zonkyio:master Apr 8, 2024
8 checks passed
@tomix26
Copy link
Collaborator

tomix26 commented Apr 8, 2024

@jakepearson Yep, of course, I'll try to release the next version soon 🙂

@jakepearson
Copy link

Thanks a bunch for the release and the fantastic library!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants