DuckDB AWS Extension是DuckDB组织的一款连接数据库与云服务的扩展组件。 DuckDB AWS Extension存在授权问题漏洞,该漏洞源于通过调用load_aws_credentials函数并将redact_secret参数设置为false,绕过数据库范围的allow_unredacted_secrets=false策略,可能导致任何具有SQL执行权限的数据库用户提取明文AWS凭证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| duckdb | duckdb-aws | < 7d04119ee8d3f8836e278f0e8cbf21827ff5338b |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| duckdb | duckdb-aws | 0 ~ 7d04119ee8d3f8836e278f0e8cbf21827ff5338b | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet