Impact
A missing authorization check in the request handling of Amazon Athena engine version 3 allowed an authenticated user to read query metadata—including AWS account identifiers and the text of SQL statements—from other AWS accounts. The vulnerability did not expose query results, credentials, or Amazon S3 data.
Affected Systems
The affected product is Amazon Athena, specifically the version 3 engine used for query handling. No specific internal sub‑products or version ranges are listed beyond this high‑level product designation.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation activity in the wild. Likely attack paths require an authenticated Athena user; the issue would allow limited metadata exposure but not data leaks or system compromise.
OpenCVE Enrichment