Rejected
Details
Assignee
UnassignedUnassignedReporter
Dareen FadulDareen FadulLabels
Components
Priority
Critical
Details
Details
Assignee
Unassigned
UnassignedReporter
Dareen Fadul
Dareen FadulLabels
Components
Priority
Created September 9, 2022 at 4:33 PM
Updated September 12, 2022 at 10:53 AM
Resolved September 12, 2022 at 10:53 AM
Hi, I noticed in hibernate-testing the following:
In OracleDatabaseCleaner.java, in clearSchema method, PreparedStatement is not used, and no input validation for variables used in the SQL command at line 101.
For example, if the user, passed (XX' OR '1'='1';--) for schemaName , then DROP TABLE statements for all schemas in the database will be generated and executed in clearSchema0.
Similar issues in other files like AbstractMySQLDatabaseCleaner.java, and DB2DatabaseCleaner.java