漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL
Vulnerability Description
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through the affected wrapper. To remediate this issue, users should upgrade to the AWS Advanced Go Wrapper release 2026-05-26
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Amazon Web Services Advanced Go Wrapper 安全漏洞
Vulnerability Description
Amazon Web Services Advanced Go Wrapper是Amazon Web Services开源的一个Go语言现有驱动程序的补充。 Amazon Web Services Advanced Go Wrapper存在安全漏洞,该漏洞源于GlobalDatabasePlugin中不可信搜索路径问题,导致远程经过身份验证的低权限攻击者通过特制函数提升权限。
CVSS Information
N/A
Vulnerability Type
N/A