Close Menu
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Surprisingly Tough Competition for Meta’s Ray-Ban

How AI assistance impacts the formation of coding skills \ Anthropic

Chip stocks rise after earnings, Nvidia H200 approved in China

Facebook X (Twitter) Instagram
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram Pinterest Vimeo
Karachi Chronicle
  • Home
  • AI
  • Business
  • Entertainment
  • Fashion
  • Politics
  • Sports
  • Tech
  • World
Karachi Chronicle
You are at:Home » Amazon Security Alert as 3 Highly Rated Vulnerabilities Impact Cloud
Tech

Amazon Security Alert as 3 Highly Rated Vulnerabilities Impact Cloud

Adnan MaharBy Adnan MaharDecember 26, 2024No Comments3 Mins Read0 Views
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Amazon Redshift vulnerability discovered – patch now

SOPA Image/LightRocket (via Getty Images)

Amazon has confirmed that three high-severity security vulnerabilities that could allow privilege escalation and the full impact this could have on a potential data breach have been identified and fixed. did. Here’s what you need to know about SQL injection issues in a number of Amazon Redshift drivers: CVE-2024-12744, CVE-2024-12745, and CVE-2024-12746

forbesDark Web Facial ID Farm Alert – Hackers Build Identity Fraud Databaseby davie winder

What is Amazon Redshift?

Amazon Redshift, part of the Amazon Web Services cloud computing platform, is a data warehousing solution that handles large dataset and database migrations and can process up to 16 petabytes of data on a single cluster. Amazon says Amazon Redshift enables near real-time analytics without building complex data pipelines, giving you the ability to “analyze petabytes of data without the burden of infrastructure management.” said. When used with SageMaker Lakehouse, Amazon Redshift’s powerful SQL analytics capabilities power tens of thousands of customers. And hackers.

forbesUrgent warning for billions of Gmail security users as attacks continueby davie winder

Description of Amazon Redshift SQL Injection Vulnerabilities CVE-2024-12744, CVE-2024-12745, and CVE-2024-12746

Amazon Web Services announced in a December 24 security bulletin that it has identified high-severity issues within the Amazon Redshift Java Database Connectivity Driver, Amazon Redshift Python Connector, and Amazon Redshift Open Database Connectivity Driver. These vulnerabilities are all officially rated 8 and affect Amazon Redshift JDBC driver version 2.1.0.31. Amazon Redshift Python Connector, version 2.1.4; Amazon Redshift ODBC Driver, version v2.1.5.0.

CVE-2024-12744 is a SQL injection issue in the RedShift JDBC driver that could allow an attacker to gain elevated privileges. Amazon says, “We recommend that customers upgrade to driver version 2.1.0.32 or revert to driver version 2.1.0.30.”

CVE-2024-12745 is another SQL injection issue, this time in the Redshift Python Connector, where an SQL command that uses externally influenced input from an upstream component modifies the intended command. It’s a matter of not disabling or disabling potential elements. “This issue is resolved in driver version 2.1.5. We recommend customers upgrade to driver version 2.1.5 or revert to driver version 2.1.3,” Amazon said.

CVE-2024-12746 affects Redshift ODBC Driver v2.1.5.0, allowing privilege escalation via a SQL injection issue when using the SQLTables or SQLColumns metadata APIs. “This issue is resolved in driver version 2.1.6.0. We recommend customers upgrade to driver version 2.1.6.0 or revert to driver version 2.1.4.0,” Amazon said.

forbesFBI warns of brute force password spying attacks—what you need to knowby davie winder

Amazon said the fixes were all made available on December 23 and encouraged all customers to upgrade to the latest version to address security vulnerabilities as soon as possible. I asked Amazon for a statement.



Source link

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
Previous ArticleSony Pictures CEO Tony Vinciquerra defends ‘Spider-Man’ spinoff
Next Article India sees $25 billion in export opportunities from US-China tariff war
Adnan Mahar
  • Website

Adnan is a passionate doctor from Pakistan with a keen interest in exploring the world of politics, sports, and international affairs. As an avid reader and lifelong learner, he is deeply committed to sharing insights, perspectives, and thought-provoking ideas. His journey combines a love for knowledge with an analytical approach to current events, aiming to inspire meaningful conversations and broaden understanding across a wide range of topics.

Related Posts

Chip stocks rise after earnings, Nvidia H200 approved in China

January 28, 2026

India is betting big on homegrown AI as Dell and NVIDIA ramp up NxtGen’s giant AI factory

January 28, 2026

Meta is blocking links to ICE listings on Facebook, Instagram, and threads

January 27, 2026
Leave A Reply Cancel Reply

Top Posts

20 Most Anticipated Sex Movies of 2025

January 22, 2025869 Views

President Trump’s SEC nominee Paul Atkins marries multi-billion dollar roof fortune

December 14, 2024134 Views

How to tell the difference between fake and genuine Adidas Sambas

December 26, 2024133 Views

Alice Munro’s Passive Voice | New Yorker

December 23, 202490 Views
Don't Miss
AI January 31, 2026

Surprisingly Tough Competition for Meta’s Ray-Ban

Thanks to Meta, everyone wants a piece of the AI glasses pie. While Ray-Ban Meta…

How AI assistance impacts the formation of coding skills \ Anthropic

Visual reasoning added to Gemini Flash models

Mozilla, OpenAI builds an AI “rebel alliance” against Anthropic

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Karachi Chronicle, your go-to source for the latest and most insightful updates across a range of topics that matter most in today’s fast-paced world. We are dedicated to delivering timely, accurate, and engaging content that covers a variety of subjects including Sports, Politics, World Affairs, Entertainment, and the ever-evolving field of Artificial Intelligence.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Surprisingly Tough Competition for Meta’s Ray-Ban

How AI assistance impacts the formation of coding skills \ Anthropic

Chip stocks rise after earnings, Nvidia H200 approved in China

Most Popular

Anthropic agrees to work with music publishers to prevent copyright infringement

December 16, 20070 Views

Elon Musk launches new UK AI technology company amid speculation he is planning to donate millions to Nigel Farage’s Reform Party

July 14, 20170 Views

chatgpt makers claim data breach claims “seriously”

July 14, 20170 Views
© 2026 karachichronicle. Designed by karachichronicle.
  • Home
  • About us
  • Advertise
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.