Close Menu
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Republican “big beautiful” budget bill means your money

The Truth Berns: How Democrats became undemocratic long before Donald Trump | World News

Instead of Timothée Chalamett or Tom Holland, Sean Penn declares the Oscar-winning actress “the last movie star.” Hollywood

Facebook X (Twitter) Instagram
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram Pinterest Vimeo
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World
Karachi Chronicle
You are at:Home » Amazon Security Alert as 3 Highly Rated Vulnerabilities Impact Cloud
Tech

Amazon Security Alert as 3 Highly Rated Vulnerabilities Impact Cloud

Adnan MaharBy Adnan MaharDecember 26, 2024No Comments3 Mins Read0 Views
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Amazon Redshift vulnerability discovered – patch now

SOPA Image/LightRocket (via Getty Images)

Amazon has confirmed that three high-severity security vulnerabilities that could allow privilege escalation and the full impact this could have on a potential data breach have been identified and fixed. did. Here’s what you need to know about SQL injection issues in a number of Amazon Redshift drivers: CVE-2024-12744, CVE-2024-12745, and CVE-2024-12746

forbesDark Web Facial ID Farm Alert – Hackers Build Identity Fraud Databaseby davie winder

What is Amazon Redshift?

Amazon Redshift, part of the Amazon Web Services cloud computing platform, is a data warehousing solution that handles large dataset and database migrations and can process up to 16 petabytes of data on a single cluster. Amazon says Amazon Redshift enables near real-time analytics without building complex data pipelines, giving you the ability to “analyze petabytes of data without the burden of infrastructure management.” said. When used with SageMaker Lakehouse, Amazon Redshift’s powerful SQL analytics capabilities power tens of thousands of customers. And hackers.

forbesUrgent warning for billions of Gmail security users as attacks continueby davie winder

Description of Amazon Redshift SQL Injection Vulnerabilities CVE-2024-12744, CVE-2024-12745, and CVE-2024-12746

Amazon Web Services announced in a December 24 security bulletin that it has identified high-severity issues within the Amazon Redshift Java Database Connectivity Driver, Amazon Redshift Python Connector, and Amazon Redshift Open Database Connectivity Driver. These vulnerabilities are all officially rated 8 and affect Amazon Redshift JDBC driver version 2.1.0.31. Amazon Redshift Python Connector, version 2.1.4; Amazon Redshift ODBC Driver, version v2.1.5.0.

CVE-2024-12744 is a SQL injection issue in the RedShift JDBC driver that could allow an attacker to gain elevated privileges. Amazon says, “We recommend that customers upgrade to driver version 2.1.0.32 or revert to driver version 2.1.0.30.”

CVE-2024-12745 is another SQL injection issue, this time in the Redshift Python Connector, where an SQL command that uses externally influenced input from an upstream component modifies the intended command. It’s a matter of not disabling or disabling potential elements. “This issue is resolved in driver version 2.1.5. We recommend customers upgrade to driver version 2.1.5 or revert to driver version 2.1.3,” Amazon said.

CVE-2024-12746 affects Redshift ODBC Driver v2.1.5.0, allowing privilege escalation via a SQL injection issue when using the SQLTables or SQLColumns metadata APIs. “This issue is resolved in driver version 2.1.6.0. We recommend customers upgrade to driver version 2.1.6.0 or revert to driver version 2.1.4.0,” Amazon said.

forbesFBI warns of brute force password spying attacks—what you need to knowby davie winder

Amazon said the fixes were all made available on December 23 and encouraged all customers to upgrade to the latest version to address security vulnerabilities as soon as possible. I asked Amazon for a statement.



Source link

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
Previous ArticleSony Pictures CEO Tony Vinciquerra defends ‘Spider-Man’ spinoff
Next Article India sees $25 billion in export opportunities from US-China tariff war
Adnan Mahar
  • Website

Adnan is a passionate doctor from Pakistan with a keen interest in exploring the world of politics, sports, and international affairs. As an avid reader and lifelong learner, he is deeply committed to sharing insights, perspectives, and thought-provoking ideas. His journey combines a love for knowledge with an analytical approach to current events, aiming to inspire meaningful conversations and broaden understanding across a wide range of topics.

Related Posts

Amazon will face Elon Musk’s Tesla with the robot launch.

May 7, 2025

This stretchy battery is healed after being cut in half

April 21, 2025

Apple fixes two zero-days exploited in targeted iPhone attacks

April 16, 2025
Leave A Reply Cancel Reply

Top Posts

President Trump’s SEC nominee Paul Atkins marries multi-billion dollar roof fortune

December 14, 202496 Views

Alice Munro’s Passive Voice | New Yorker

December 23, 202453 Views

20 Most Anticipated Sex Movies of 2025

January 22, 202542 Views

2025 Best Actress Oscar Predictions

December 12, 202434 Views
Don't Miss
AI April 14, 2025

Google, Nvidia invests in AI startup Safe Superintelligence, co-founder of Openai Ilya Sutskever

Alphabet and Nvidia are investing in Safe Superintelligence (SSI), a stealth mode AI startup co-founded…

This $30 billion AI startup can be very strange by a man who said that neural networks may already be aware of it

As Deepseek and ChatGpt Surge, is Delhi behind?

Openai’s Sam Altman reveals his daily use of ChatGpt, and that’s not what you think

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Karachi Chronicle, your go-to source for the latest and most insightful updates across a range of topics that matter most in today’s fast-paced world. We are dedicated to delivering timely, accurate, and engaging content that covers a variety of subjects including Sports, Politics, World Affairs, Entertainment, and the ever-evolving field of Artificial Intelligence.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Republican “big beautiful” budget bill means your money

The Truth Berns: How Democrats became undemocratic long before Donald Trump | World News

Instead of Timothée Chalamett or Tom Holland, Sean Penn declares the Oscar-winning actress “the last movie star.” Hollywood

Most Popular

ATUA AI (TUA) develops cutting-edge AI infrastructure to optimize distributed operations

October 11, 20020 Views

10 things you should never say to an AI chatbot

November 10, 20040 Views

Character.AI faces lawsuit over child safety concerns

December 12, 20050 Views
© 2025 karachichronicle. Designed by karachichronicle.
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.