{"id":"GHSA-7xw4-g7mm-r4hh","summary":"Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance","details":"### Description of Vulnerability:\nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends for customers to upgrade to the following versions: AWS JDBC Wrapper to v2.6.5 or greater.\n\n\n### Source of Vulnerability Report: \nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS JDBC Wrapper \u003c 2.6.5\n\n### Platforms: \nMacOS/Windows/Linux","modified":"2026-01-30T02:26:08.110687Z","published":"2025-11-13T22:22:28Z","related":["CVE-2025-12967"],"database_specific":{"github_reviewed_at":"2025-11-13T22:22:28Z","nvd_published_at":null,"cwe_ids":["CWE-470"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-7xw4-g7mm-r4hh"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/commit/b62183b851fa46f891f9fe9c861e9ac2fb7d8b62"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-jdbc-wrapper"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/2.6.5"}],"affected":[{"package":{"name":"software.amazon.jdbc:aws-advanced-jdbc-wrapper","ecosystem":"Maven","purl":"pkg:maven/software.amazon.jdbc/aws-advanced-jdbc-wrapper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.5"}]}],"versions":["1.0.0","1.0.1","1.0.2","2.0.0","2.1.0","2.1.1","2.1.2","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2.4.0","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.6.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-7xw4-g7mm-r4hh/GHSA-7xw4-g7mm-r4hh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}