Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39180
HistoryFeb 09, 2023 - 9:07 a.m.

SQL Injection

2023-02-0909:07:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
apache age
sql injection
postgresql

EPSS

0.001

Percentile

45.0%

Apache Age is vulnerable to SQL Injection attacks. A specifically crafted attack statement through the cypher function allows a malicious user to inject and execute arbitrary SQL queries on the target system due to the failure to fully utilize parameterization. This only impacts PostgreSQL 11 and 12, and to fully patch you must upgrade the Age extension to >= 1.2.0.

EPSS

0.001

Percentile

45.0%

Related for VERACODE:39180