String Concatenation with Event Data
Lambda event fields are directly concatenated into SQL strings using StringBuilder, String.format, or + operator.
SQL injection vulnerability where untrusted Lambda event fields are concatenated into SQL strings (e.g., StringBuilder or String.format) instead of using parameterized statements, potentially allowing attackers to read, modify, or delete database records, escalate privileges, or run destructive queries.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
Lambda event fields are directly concatenated into SQL strings using StringBuilder, String.format, or + operator.
Sourcery automatically identifies sql injection from event data in sql string in aws lambda and many other security issues in your codebase.