CVE-2025-12967: High severity AWS JDBC Wrapper vulnerability
Description of Vulnerability:
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rdssuperuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
AWS recommends customers upgrade to the following versions: AWS Python Wrapper to v1.4.0
Source of Vulnerability Report: Allistair Ishmael Hakim <allistair.hakim@gmail.com>
Affected products & versions: AWS Python Wrapper < 1.4.0
Platforms: MacOS/Windows/Linux
Other sources
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rdssuperuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5, AWS Go Wrapper to 2025-10-17, AWS NodeJS Wrapper to v2.0.1, AWS Python Wrapper to v1.4.0 and AWS PGSQL ODBC driver to v1.0.1
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/aws_advanced_python_wrapperto a version that resolves this vulnerability.Fixed in 1.4.0 - Upgrade
Upgrade
AWS Python Wrapperto a version that resolves this vulnerability.Fixed in 1.4.0 - Upgrade
Upgrade
AWS JDBC Wrapperto a version that resolves this vulnerability.Fixed in 2.6.5 - Upgrade
Upgrade
AWS Go Wrapperto a version that resolves this vulnerability.Fixed in 2025-10-17 - Upgrade
Upgrade
AWS NodeJS Wrapperto a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
AWS PGSQL ODBC driverto a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12967?
CVE-2025-12967 has a low severity rating but poses a risk of privilege escalation to the rds_superuser role.
Who is affected by CVE-2025-12967?
CVE-2025-12967 affects users of the AWS Wrappers for Amazon Aurora PostgreSQL, including those using AWS JDBC, Go, NodeJS, Python, and PGSQL ODBC drivers.
How do I fix CVE-2025-12967?
To fix CVE-2025-12967, upgrade to the latest versions of the affected AWS Wrappers as recommended by Amazon.
What type of vulnerability is CVE-2025-12967?
CVE-2025-12967 is a privilege escalation vulnerability that can be exploited by low privilege authenticated users.
What actions can be taken to mitigate CVE-2025-12967?
Mitigation for CVE-2025-12967 includes restricting access and properly managing user privileges in Amazon RDS configurations.