Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.
The error results from insufficient default transport security (CWE-295 — improper certificate validation) in components responsible for connecting with identity providers. An attacker positioned on the network communication path (man-in-the-middle) can impersonate a legitimate identity provider server, because the driver does not properly verify the TLS certificate of the server. As a result, it is possible to intercept transmitted authentication credentials. The vulnerability affects only connections with external identity providers — direct connections to Amazon Athena are not exposed.
An attacker can intercept user authentication credentials (e.g., tokens, passwords) transmitted to external identity providers, which may lead to unauthorized access to resources protected by these credentials.
Update the Amazon Athena ODBC driver to version 2.1.0.0 or later. Installation packages for Linux, macOS (Intel and ARM), and Windows systems are available in the vendor's references (AWS Security Bulletin 2026-013).
Amazon Athena ODBC Driver in versions before 2.1.0.0 on Linux, macOS (Intel and ARM), and Microsoft Windows platforms — only in configurations using external identity providers.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAmazon Athena Odbc
APPAmazon< 2.1.0.0Apple macOS
OSAppleall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP