CyberRota Analysis
AI-GeneratedThe vulnerability arises from improper handling of XML external entity references in the RemoteQueryCachePlugin of AWS Advanced JDBC Wrapper versions 3.3.0 to 4.2.0. This flaw could allow an attacker with write access to the shared cache to extract sensitive information, such as database and IAM role credentials, by exploiting crafted XML data in cached query results. Organizations utilizing affected versions should prioritize upgrading to version 4.3.0 or later to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value. To remediate this issue, users should upgrade to version 4.3.0 or later.