Issue with RedShift JDBC Drive... Note

Issue with RedShift JDBC Driver, Python Connector and ODBC Driver - (CVE-2024-12744, CVE-2024-12745, CVE-2024-12746)

On December 23, 2024, AWS released a fix for the Amazon Redshift JDBC Driver, Python Connector, and ODBC Driver to address several security issues. The Amazon Redshift JDBC Driver version 2.1.0.31 has a SQL injection vulnerability in the getSchemas, getTables, or getColumns Metadata APIs, which has been fixed in version 2.1.0.32. The Python Connector version 2.1.4 has a similar issue resolved in version 2.1.5. The ODBC Driver version 2.1.5.0 also has a SQL injection problem, resolved in version 2.1.6.0. Affected users are recommended to upgrade to the latest versions or revert to previous secure versions. For the JDBC Driver, users should switch to version 2.1.0.32 or 2.1.0.30. For the Python Connector, version 2.1.5 or 2.1.3 is recommended. ODBC Driver users should move to version 2.1.6.0 or 2.1.4.0. Any security concerns or questions should be directed to [email protected].