AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High severity
GitHub Reviewed
Published
Nov 10, 2025
in
aws/aws-advanced-python-wrapper
•
Updated Nov 13, 2025
Description
Published by the National Vulnerability Database
Nov 10, 2025
Published to the GitHub Advisory Database
Nov 13, 2025
Reviewed
Nov 13, 2025
Last updated
Nov 13, 2025
Description of Vulnerability:
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
AWS recommends customers upgrade to the following versions: AWS Python Wrapper to v1.4.0
Source of Vulnerability Report:
Allistair Ishmael Hakim [email protected]
Affected products & versions:
AWS Python Wrapper < 1.4.0
Platforms:
MacOS/Windows/Linux
References