CVE-2025-5279
Description
A flaw was found in the Amazon Redshift Python Connector. This vulnerability allows an attacker to intercept the token exchange process and retrieve an access token via an insecure connection to the Identity Provider when the BrowserAzureOAuth2CredentialsProvider plugin is used.
Statement
This vulnerability is rated as an IMPORTANT severity because this vulnerability exists in the Amazon Redshift Python Connector, when configured with the BrowserAzureOAuth2CredentialsProvider plugin, this issue arises because the driver skips the SSL certificate validation step for the Identity Provider during the token exchange process, an insecure connection could allow an attacker to intercept communications and retrieve an access token.
Understanding the Weakness (CWE)
Integrity,Authentication
Technical Impact: Bypass Protection Mechanism; Gain Privileges or Assume Identity
When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The product might connect to a malicious host while believing it is a trusted host, or the product might be deceived into accepting spoofed data that appears to originate from a trusted host.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.