Home

Description

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

PUBLISHED Reserved 2024-08-21 | Published 2025-06-12 | Updated 2025-06-17 | Assigner mitre

References

github.com/go-pg/pg

media.defcon.org/...ggling Queries at the Protocol Level.pdf

github.com/...d06cf2b92183b49188b7c922/types/append_value.go

www.sonarsource.com/...-trouble-a-subtle-sql-injection-flaw/

cve.org (CVE-2024-44905)

nvd.nist.gov (CVE-2024-44905)

Download JSON