Vulnerability Report: GO-2024-2605

SQL injection is possible when the database uses the non-default simple protocol, a minus sign directly precedes a numeric placeholder followed by a string placeholder on the same line, and both parameter values are user-controlled.

For detailed information about this vulnerability, visit https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL