{"id":"GHSA-7xw4-g7mm-r4hh","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7xw4-g7mm-r4hh","summary":"Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance","details":"### Description of Vulnerability:\nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends for customers to upgrade to the following versions: AWS JDBC Wrapper to v2.6.5 or greater.\n\n\n### Source of Vulnerability Report: \nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS JDBC Wrapper < 2.6.5\n\n### Platforms: \nMacOS/Windows/Linux","published":"2025-11-13T22:22:28Z","modified":"2026-02-04T04:18:45.781949Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"software.amazon.jdbc:aws-advanced-jdbc-wrapper","fixedVersion":"2.6.5"}],"fix":{"url":"https://github.com/aws/aws-advanced-jdbc-wrapper/commit/b62183b851fa46f891f9fe9c861e9ac2fb7d8b62","label":"aws/aws-advanced-jdbc-wrapper@b62183b"},"references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-7xw4-g7mm-r4hh"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/commit/b62183b851fa46f891f9fe9c861e9ac2fb7d8b62"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-jdbc-wrapper"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/2.6.5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T04:18:45.781949Z"}}