redshift_connector is vulnerable to Code Injection
98
Critical Risk
Affected versions are vulnerable to an input validation flaw in amazon-redshift-python-driver query result processing. A rogue server or man-in-the-middle attacker could send crafted PostgreSQL protocol responses that may lead to arbitrary code execution on the client, potentially allowing command execution, file access, or credential theft.
You are affected if you are using a version that falls within the vulnerable range.
redshift_connector is vulnerable to Code Injection in versions 0.0.1 - 2.1.13.
Upgrade the redshift_connector library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant