VDB
Sign up
HIGH8.0

GHSA-8wj8-cfxr-9374

AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Quick fix

GHSA-8wj8-cfxr-9374 — aws-advanced-nodejs-wrapper: upgrade to the fixed version with the command below.

npm install aws-advanced-nodejs-wrapper@2.0.1

Details

### Description of Vulnerability: An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.

AWS recommends that customers upgrade to the following version: AWS NodeJS Wrapper to v2.0.1.

### Source of Vulnerability Report: Allistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)

### Affected products & versions: AWS NodeJS Wrapper < 2.0.1.

### Platforms: MacOS/Windows/Linux

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/aws-advanced-nodejs-wrapper
Introduced in: 0Fixed in: 2.0.1
Fixnpm install aws-advanced-nodejs-wrapper@2.0.1

References