aws-advanced-jdbc-wrapper is vulnerable to Insecure Default Variable Initialization
15
Low Risk
Affected versions of this package are vulnerable due to an unsafe default value for the SSL Insecure parameter, which disables server certificate verification during SAML assertion workflows. This can expose applications to man-in-the-middle attacks. The parameter should default to false to ensure secure SSL connections.
You are affected if you are using a version that falls within the vulnerable range.
aws-advanced-jdbc-wrapper is vulnerable to Insecure Default Variable Initialization in versions 2.3.2 - 2.5.5.
Upgrade the software.amazon.jdbc:aws-advanced-jdbc-wrapper library to the patch version and/or set sslInsecure to false.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant