GHSA-8wj8-cfxr-9374
AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance
Quick fix
GHSA-8wj8-cfxr-9374 — aws-advanced-nodejs-wrapper: upgrade to the fixed version with the command below.
npm install aws-advanced-nodejs-wrapper@2.0.1Details
### Description of Vulnerability: An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
AWS recommends that customers upgrade to the following version: AWS NodeJS Wrapper to v2.0.1.
### Source of Vulnerability Report: Allistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)
### Affected products & versions: AWS NodeJS Wrapper < 2.0.1.
### Platforms: MacOS/Windows/Linux
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.0.1npm install aws-advanced-nodejs-wrapper@2.0.1