diff --git a/advisories/github-reviewed/2025/11/GHSA-7xw4-g7mm-r4hh/GHSA-7xw4-g7mm-r4hh.json b/advisories/github-reviewed/2025/11/GHSA-7xw4-g7mm-r4hh/GHSA-7xw4-g7mm-r4hh.json index e437188e81245..8127cdc34f7ac 100644 --- a/advisories/github-reviewed/2025/11/GHSA-7xw4-g7mm-r4hh/GHSA-7xw4-g7mm-r4hh.json +++ b/advisories/github-reviewed/2025/11/GHSA-7xw4-g7mm-r4hh/GHSA-7xw4-g7mm-r4hh.json @@ -3,7 +3,9 @@ "id": "GHSA-7xw4-g7mm-r4hh", "modified": "2025-11-13T22:22:28Z", "published": "2025-11-13T22:22:28Z", - "aliases": [], + "aliases": [ + "CVE-2025-12967" + ], "summary": "Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance", "details": "### Description of Vulnerability:\nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends for customers to upgrade to the following versions: AWS JDBC Wrapper to v2.6.5 or greater.\n\n\n### Source of Vulnerability Report: \nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS JDBC Wrapper < 2.6.5\n\n### Platforms: \nMacOS/Windows/Linux", "severity": [