Skip to content

Conversation

@00felix-app
Copy link

@00felix-app 00felix-app bot commented Aug 6, 2025

Upgrade org.postgresql:postgresql from 42.3.1 to 42.3.9

This pull request upgrades org.postgresql:postgresql from version 42.3.1 to 42.3.9 to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.
Vulnerabilities Addressed

Vulnerability Description
CVE-2022-21724 pgjdbc Does Not Check Class Instantiation when providing Plugin Classes. pgjdbc Does Not Check Class Instantiation when providing Plugin Classes

| CVE-2022-26520 | Path traversal in org.postgresql:postgresql. Path traversal in org.postgresql:postgresql |

| GHSA-673j-qm5f-xpv8 | pgjdbc Arbitrary File Write Vulnerability. |

| CVE-2022-31197 | PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names. PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names |

| CVE-2022-41946 | TemporaryFolder on unix-like systems does not limit access to created files. TemporaryFolder on unix-like systems does not limit access to created files |

| CVE-2024-1597 | org.postgresql:postgresql vulnerable to SQL Injection via line comment generation. org.postgresql:postgresql vulnerable to SQL Injection via line comment generation |

This upgrade enhances the security and stability of the org.postgresql:postgresql dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant