Junglewise Threat Intelligence

CVE-2024-27304: GO-2024-2606 - SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx

CVE-2024-27304 · Severity: low · CVSS 3.1 · Published 2024-03-14

Technologies: github.com/jackc/pgproto3/v2 (Go), github.com/jackc/pgx (Go), github.com/jackc/pgx/v5 (Go), github.com/jackc/pgx/v4 (Go). Vendors: Go.

Executive brief

SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx

Affected products

  • Go github.com/jackc/pgproto3/v2
  • Go github.com/jackc/pgx
  • Go github.com/jackc/pgproto3
  • Go github.com/jackc/pgx/v5
  • Go github.com/jackc/pgx/v4

Related threats