Description
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5, AWS Go Wrapper to 2025-10-17, AWS NodeJS Wrapper to v2.0.1, AWS Python Wrapper to v1.4.0 and AWS PGSQL ODBC driver to v1.0.1
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
Passive
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- AWS / Go Wrapper2025-10-17 – 2025-10-17
- AWS / JDBC Wrapper2.6.5 – 2.6.5
- AWS / NodeJS Wrapper2.0.1 – 2.0.1
- AWS / ODBC driver1.0.1 – 1.0.1
- AWS / Python Wrapper1.4.0 – 1.4.0
References
- MISChttps://aws.amazon.com/security/security-bulletins/AWS-2025-028/
- PATCHhttps://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/2.6.5
- PATCHhttps://github.com/aws/aws-advanced-go-wrapper/releases/tag/release-2025-10-17
- PATCHhttps://github.com/aws/aws-advanced-python-wrapper/releases/tag/1.4.0
- PATCHhttps://github.com/aws/aws-pgsql-odbc/releases/tag/1.0.1
- PATCHhttps://github.com/aws/aws-advanced-nodejs-wrapper/releases/tag/2.0.1
- VENDOR_ADVISORYhttps://github.com/aws/aws-advanced-python-wrapper/security/advisories/GHSA-4jvf-wx3f-2x8q
- VENDOR_ADVISORYhttps://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-7xw4-g7mm-r4hh
- VENDOR_ADVISORYhttps://github.com/aws/aws-pgsql-odbc/security/advisories/GHSA-q327-fgm8-7mxf
- VENDOR_ADVISORYhttps://github.com/aws/aws-advanced-go-wrapper/security/advisories/GHSA-7wq2-32h4-9hc9
- VENDOR_ADVISORYhttps://github.com/aws/aws-advanced-nodejs-wrapper/security/advisories/GHSA-8wj8-cfxr-9374