aws-qldb-ledger-partiql-results

PartiQL query results can expose arbitrary ledger documents containing credentials or sensitive data.

awscritical service: aws:qldb emits CanReadData

Where it sits

locationqldb-session:SendCommand.ExecuteStatement.Result.FirstPage.Values[]
location kinddata_record
data kindscredential password api_key customer_data pii
emits edgeCanReadData
serviceQLDB (aws:qldb)

Collection recipe

access modedata_plane
operationSendCommand (ExecuteStatement)
response pathExecuteStatement.Result.FirstPage.Values[]
encodingbinary
params{"ExecuteStatement": {"Statement": "\u003cSELECT\u003e", "TransactionId": "\u003ctx-id\u003e"}, "SessionToken": "\u003csession-token\u003e"}

Required permissions

qldb:SendCommand
qldb:PartiQLSelect

References

move · open · esc close