chore: upgrade org.postgresql:postgresql #11
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Upgrade
org.postgresql:postgresqlfrom42.3.1to42.3.9This pull request upgrades
org.postgresql:postgresqlfrom version42.3.1to42.3.9to address multiple security vulnerabilities and ensure compliance with security best practices. The upgrade has been tested locally to confirm compatibility with existing functionality.Vulnerabilities Addressed
| CVE-2022-26520 | Path traversal in org.postgresql:postgresql. Path traversal in org.postgresql:postgresql |
| GHSA-673j-qm5f-xpv8 | pgjdbc Arbitrary File Write Vulnerability. |
| CVE-2022-31197 | PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names. PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names |
| CVE-2022-41946 | TemporaryFolder on unix-like systems does not limit access to created files. TemporaryFolder on unix-like systems does not limit access to created files |
| CVE-2024-1597 | org.postgresql:postgresql vulnerable to SQL Injection via line comment generation. org.postgresql:postgresql vulnerable to SQL Injection via line comment generation |
This upgrade enhances the security and stability of the
org.postgresql:postgresqldependency.