When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. This issue has been addressed in driver version 2.1.7. Users should upgrade to address this issue and ensure any forked or derivative code is patched to incorporate the new fixes.
History

Sat, 31 May 2025 02:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Important


Tue, 27 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 20:30:00 +0000

Type Values Removed Values Added
Description When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. This issue has been addressed in driver version 2.1.7. Users should upgrade to address this issue and ensure any forked or derivative code is patched to incorporate the new fixes.
Title Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published: 2025-05-27T20:17:21.228Z

Updated: 2025-05-27T20:26:51.137Z

Reserved: 2025-05-27T15:12:06.044Z

Link: CVE-2025-5279

cve-icon Vulnrichment

Updated: 2025-05-27T20:26:46.720Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-27T21:15:23.370

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-5279

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-27T20:17:21Z

Links: CVE-2025-5279 - Bugzilla