bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: ClickHouse Connector

show all
Thursday, August 20, 2026

AWS Athena ClickHouse Connector Vulnerability Requires Immediate Update

AWS Athena's ClickHouse connector (versions before v2026.17.1) has a privilege escalation bug that lets authenticated users steal AWS Secrets Manager secrets. An attacker could redirect the connector to read arbitrary secrets by manipulating the connection string. You need to upgrade to v2026.17.1 or later immediately if you're using Athena Query Federation with ClickHouse.

source: [aws/security-bulletin]