PT-2026-79118 · Amazon · Amazon Athena Federated Query Clickhouse Connector
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Amazon Athena Federated Query ClickHouse connector versions prior to v2026.17.1
Description
Incorrect privilege assignment in the deployment template allows an authenticated remote user to read arbitrary AWS Secrets Manager secrets within the deploying account. An attacker can achieve this by directing the connector's connection string toward an unrelated secret and a database endpoint under their control, which leads the connector to transmit the secret to that endpoint.
Recommendations
Upgrade to aws-athena-query-federation connectors version v2026.17.1 or later.
Redeploy the connector using the current template and provide a non-empty
SecretNamePrefix value.Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Athena Federated Query Clickhouse Connector