Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/murataydemir/cve-2022-41828
Vulnerability AnalysisExploitationWeb Application ExploitationCloud SecurityLearning & EducationDatabase Security
GitHubmurataydemir/cve-2022-41828

CVE-2022-41828

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)

View Repository
4273 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)


Platform Badge Ecosystem

The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. The Driver provides access to Redshift from any Java application, application server, or Java-enabled applet.

A potential remote command execution issue exists within redshift-jdbc42 versions 2.1.0.7 and below. When plugins are used with the driver, it instantiates plugin instances based on Java class names provided via the sslhostnameverifier, socketFactory, sslfactory, and sslpasswordcallback connection properties. In affected versions, the driver does not verify if a plugin class implements the expected interface before instantiatiaton. This can lead to loading of arbitrary Java classes, which a knowledgeable attacker with control over the JDBC URL can use to achieve remote code execution.

Patches

This issue is patched within redshift-jdbc-42 version 2.1.0.8 and above

Workarounds

AWS advises customers using plugins to upgrade to redshift-jdbc42 version 2.1.0.8 or above. There are no known workarounds for this issue.

Patch analysis: GitHub issue and related commits

In order to fix this issue, modifications have been made in 4 different Java classes in commit aws/amazon-redshift-jdbc-driver@9999659. These classes are as follows, respectively.

  • src/main/java/com/amazon/redshift/core/SocketFactoryFactory.java
@@ -38,7 +38,7 @@ public static SocketFactory getSocketFactory(Properties info) throws RedshiftExc
      return SocketFactory.getDefault();
    }
    try {
      //removed return (SocketFactory) ObjectFactory.instantiate(socketFactoryClassName, info, true, RedshiftProperty.SOCKET_FACTORY_ARG.get(info));
      return ObjectFactory.instantiate(SocketFactory.class, socketFactoryClassName, info, true, RedshiftProperty.SOCKET_FACTORY_ARG.get(info)); //added
    } catch (Exception e) {
      throw new RedshiftException(
@@ -66,7 +66,7 @@ public static SSLSocketFactory getSslSocketFactory(Properties info) throws Redsh
      if (classname.equals(RedshiftConnectionImpl.NON_VALIDATING_SSL_FACTORY))
      		classname = NonValidatingFactory.class.getName();

      //removed return (SSLSocketFactory) ObjectFactory.instantiate(classname, info, true, RedshiftProperty.SSL_FACTORY_ARG.get(info));
      return  ObjectFactory.instantiate(SSLSocketFactory.class, classname, info, true, RedshiftProperty.SSL_FACTORY_ARG.get(info)); //added
    } catch (Exception e) {
      throw new RedshiftException(

commit-1

  • src/main/java/com/amazon/redshift/ssl/LibPQFactory.java
@@ -61,7 +61,7 @@ private CallbackHandler getCallbackHandler(Properties info) throws RedshiftExcep
    String sslpasswordcallback = RedshiftProperty.SSL_PASSWORD_CALLBACK.get(info);
    if (sslpasswordcallback != null) {
      try {
        //removed cbh = (CallbackHandler) ObjectFactory.instantiate(sslpasswordcallback, info, false, null);
        cbh =  ObjectFactory.instantiate(CallbackHandler.class, sslpasswordcallback, info, false, null); //added
      } catch (Exception e) {
        throw new RedshiftException(
          GT.tr("The password callback class provided {0} could not be instantiated.",

commit-2

  • src/main/java/com/amazon/redshift/ssl/MakeSSL.java
@@ -59,7 +59,7 @@ private static void verifyPeerName(RedshiftStream stream, Properties info, SSLSo
      sslhostnameverifier = "RedshiftjdbcHostnameVerifier";
    } else {
      try {
        //removed hvn = (HostnameVerifier) instantiate(sslhostnameverifier, info, false, null);
        hvn = instantiate(HostnameVerifier.class, sslhostnameverifier, info, false, null); //added
      } catch (Exception e) {
        throw new RedshiftException(
            GT.tr("The HostnameVerifier class provided {0} could not be instantiated.",

commit-3

  • src/main/java/com/amazon/redshift/util/ObjectFactory.java
@@ -34,13 +34,13 @@ public class ObjectFactory {
   * @throws IllegalAccessException if something goes wrong
   * @throws InvocationTargetException if something goes wrong
   */
  //removed public static Object instantiate(String classname, Properties info, boolean tryString,
  public static <T> T instantiate(Class<T> expectedClass, String classname, Properties info, boolean tryString, //added
      String stringarg) throws ClassNotFoundException, SecurityException, NoSuchMethodException,
          IllegalArgumentException, InstantiationException, IllegalAccessException,
          InvocationTargetException {
    Object[] args = {info};
    Constructor<?> ctor = null; //removed
    Class<?> cls = Class.forName(classname); //removed
    Constructor<? extends T> ctor = null; //added
    Class<? extends T> cls = Class.forName(classname).asSubclass(expectedClass); //added    
    try {
      ctor = cls.getConstructor(Properties.class);
    } catch (NoSuchMethodException nsme) {

commit-4

Reproducing: Developing vulnerable application and exploitation steps

To reproduce CVE-2022-41828, a vulnerable Java application with Spring framework uses a vulnerable redshift-jdbc42 version 2.1.0.7 driver as the external library is developed.

Download Tool