Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Tuesday April 12 2022, @09:03PM   Printer-friendly

Amazon RDS Vulnerability Led to Exposure of Credentials:

Amazon Web Services (AWS) on Monday announced that it recently addressed a vulnerability in Amazon Relational Database Service (RDS) that could lead to the exposure of internal credentials.

Amazon RDS is a managed database service that offers support for several database engines, including Amazon Aurora, AWS's own database engine, which offers support for MySQL and PostgreSQL.

The addressed security issue was identified in the Aurora PostgreSQL engine, more specifically in the third-party open-source PostgreSQL extension "log_fdw," which allows a user to leverage the SQL interface to access the database engine log, as well as to build foreign tables.

[...] The log_fdw extension, AWS also notes, is pre-installed in both Aurora PostgreSQL and Amazon RDS for PostgreSQL. A privileged, authenticated user able to trigger the bug could use the leaked credentials to gain elevated access to database resources.

"They would not be able to use the credentials to access internal RDS services or move between databases or AWS accounts. The credentials could only be used to access resources associated with the Aurora database cluster from which the credentials were retrieved," AWS notes.

The researcher reported the vulnerability to Amazon on December 9, 2021. An initial patch was released on December 14, but roughly three months were needed to deploy the fix to all customers.

The company updated both Aurora PostgreSQL and RDS for PostgreSQL to resolve the issue and also deprecated a series of minor versions, preventing users from creating new instances with those versions.


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 2) by Freeman on Wednesday April 13 2022, @01:51PM

    by Freeman (732) Subscriber Badge on Wednesday April 13 2022, @01:51PM (#1236590) Journal

    the cloud knows all, wait a minute, we are so screwed.

    --
    Joshua 1:9 "Be strong and of a good courage; be not afraid, neither be thou dismayed: for the Lord thy God is with thee"
(1)