Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infras…
Medium CVSS 5.9
Summary
Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value. To remediate this issue, users should upgrade to version 4.3.0 or later.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://aws.amazon.com/security/security-bulletins/2026-109-aws/ Patch
- https://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/4.3.0 Release Notes
- https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-fpvp-qwgm-v6h9 Vendor Advisory
Timeline
- nvd_ingest NVD