AWS Advanced JDBC Wrapper 版本 3.3.0 至 4.2.0 中,RemoteQueryCachePlugin 对 XML 外部实体引用的限制不当。该缺陷可能导致具有共享缓存基础设施写权限的攻击者,通过向缓存的列值中注入特制的 XML 数据,披露读取缓存查询结果的应用程序主机上的敏感文件,其中包括存储的数据库凭据和 IAM 角色凭据。 修复建议 为修复此问题,用户应升级至 4.3.0 或更高版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS Advanced JDBC Wrapper | 3.3.0 ~ 4.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89066 | 7.8 HIGH | OS command injection in the task synthesis component in projen |
| CVE-2026-89065 | 7.1 HIGH | Relative path traversal in the generated file manifest cleanup component in projen |
| CVE-2026-89090 | 5.9 MEDIUM | Denial of service in the event stream header decoder in AWS SDK for Go v2 |
No comments yet