RHSA-2023:0318: Moderate: postgresql-jdbc security update
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names (CVE-2022-31197) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0318?
The vulnerability RHSA-2023:0318 is classified as moderate.
How do I fix RHSA-2023:0318?
To fix RHSA-2023:0318, update your postgresql-jdbc package to version 42.2.18-6.el9_1.
What are the risks associated with RHSA-2023:0318?
RHSA-2023:0318 poses a risk of SQL injection through the ResultSet.refreshRow() method.
Which package is affected by RHSA-2023:0318?
The postgresql-jdbc package is affected by the vulnerability RHSA-2023:0318.
Is there a workaround for RHSA-2023:0318?
There is no specific workaround for RHSA-2023:0318; it is recommended to apply the update.