AWS Advanced JDBC Wrapper XXE Vulnerability Requires Immediate Patching
AWS Advanced JDBC Wrapper versions 3.3.0–4.2.0 contain a critical XXE flaw in RemoteQueryCachePlugin that could leak database and IAM credentials. If you're using this library with shared caching enabled, update immediately—attackers with cache write access can inject malicious XML to exploit XML parsers. This one's serious: patch your Aurora, RDS MySQL, and RDS MariaDB connections ASAP.
source: [aws/security-bulletin]