CVE-2024-12744: Amazon Web Services Redshift Java Database Connectivity Driver

High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.

Affected products

  • Amazon Amazon Web Services Redshift Java Database Connectivity Driver: version 2.1.0.31 only

Published 2024-12-24. Last modified 2026-06-17.