Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3568 | A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3. |
Github GHSA |
GHSA-8gc2-vq6m-rwjw | Amazon Redshift Python Connector vulnerable to SQL Injection |
Thu, 11 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon redshift Connector |
|
| CPEs | cpe:2.3:a:amazon:redshift_connector:2.1.4:*:*:*:*:python:*:* | |
| Vendors & Products |
Amazon
Amazon redshift Connector |
Tue, 14 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 26 Dec 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Dec 2024 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Dec 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3. | |
| Title | SQL Injection in the Amazon Redshift Python Connector affecting v2.1.4 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2025-10-14T18:58:13.925Z
Reserved: 2024-12-18T01:02:13.095Z
Link: CVE-2024-12745
Updated: 2024-12-25T02:38:55.288Z
Status : Analyzed
Published: 2024-12-24T17:15:08.150
Modified: 2025-12-11T18:32:13.417
Link: CVE-2024-12745
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA