GHSA-r38f-c4h4-hqq2 · 深刻度: high · エコシステム: maven — PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. This could lead to executing additional SQL commands as the application's JDBC user. User applications that do not invoke the `ResultSet.refreshRow()` method are not impacted. User application that do invoke that method are impacted if the underlying database that they are querying via their JDBC application may be under the control of an attacker. The attack requires the attacker to trick the user into executing SQL against a table name who's column names would contain the malicious SQL and subsequently invoke the `refreshRow()` method on the ResultSet. Note that the application's JDBC user and the schema owner need not be the same. A JDBC application that executes as a privileged user querying database schemas owned by potentially malicious less-privileged users would be vulnerable. In that situation it may be possible for the malicious user to craft a schema that causes the application to execute commands as the privileged user. Patched versions will be released as `42.2.26` and `42.4.1`. Users are advised to upgrade. There are no known workarounds for this issue.
総合評価: CVE-2022-31197 は悪用リスクが高い(68.3/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 1.66%、74 パーセンタイル) 根拠: 公開エクスプロイトが 1 件参照されています(Exploit-DB)。 推奨対応: 公開エクスプロイトが確認されています。影響範囲の確認、緩和策の適用、パッチ適用を優先してください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
| EDB-ID | ソース | 種別 | 公開 | リンク |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.46% | 1.66% | -0.80% |
| 2 | 2026-05-22 | 3.31% | 2.46% | -0.85% |
| 3 | 2026-05-08 | — | 3.31% | — |
EPSS の全履歴 (全 35 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
1.2 | 5.9 | [email protected] |
| 8.0 | 3.1 | HIGH |
|
2.1 | 5.9 | [email protected] |
GHSA-r38f-c4h4-hqq2 · 深刻度: high · エコシステム: maven — PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2022-31197: 1 source package rows (java-postgresql-jdbc); 7 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2022-31197 |
debian
|
not yet assigned | CVE-2022-31197 not yet assigned priority: Debian including 1 source packages (libpgjava), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2022-31197 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2022-31197 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2022-31197/ |
ubuntu
|
medium | CVE-2022-31197 medium priority: Ubuntu including 1 source packages (libpgjava), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 8, ignored 5. | https://ubuntu.com/security/CVE-2022-31197 |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| postgresql | postgresql_jdbc_driver | < 42.2.26 | cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:* |
| postgresql | postgresql_jdbc_driver | >= 42.3.0, < 42.3.7 | cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:* |
| postgresql | postgresql_jdbc_driver | 42.4.0 | cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.0:-:*:*:*:*:*:* |
| postgresql | postgresql_jdbc_driver | 42.4.0 | cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.0:rc1:*:*:*:*:*:* |
| postgresql | postgresql_jdbc_driver | 42.4.1 | cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.1:rc1:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 35 | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
| fedoraproject | fedora | 36 | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |