Amazon Redshift JDBC Driver <=2.1.0.8 Object Factory type-check flaw
CVE-2022-41828 Published on September 29, 2022

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

Github Repository NVD

Vulnerability Analysis

CVE-2022-41828 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Incorrect Type Conversion or Cast

The software does not correctly convert an object, resource, or structure from one type to a different type.


Products Associated with CVE-2022-41828

Want to know whenever a new CVE is published for Amazon Web Services Redshift Java Database Connectivity Driver? stack.watch will email you.

 

Vulnerable Packages

The following package name and versions may be associated with CVE-2022-41828

Package Manager Vulnerable Package Versions Fixed In
maven com.amazon.redshift:redshift-jdbc42 < 2.1.0.8 2.1.0.8

Exploit Probability

EPSS
9.64%
Percentile
93.03%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.