AWS Security ChangesHomeSearch

AWS AmazonRDS: MariaDB 12.3: Replication auth info hidden by default

Service: AmazonRDS · 2026-08-12 · Documentation medium

File: AmazonRDS/latest/UserGuide/MariaDB.Concepts.FeatureNonSupport.md · Type: information_leak

Summary

Added note that SHOW REPLICA HOSTS no longer exposes user/password information due to removed show_slave_auth_info parameter.

Security assessment

Prevents accidental exposure of replication credentials in command output, reducing credential theft risk.

Evidence

The `show_slave_auth_info` variable isn't available in the `mariadb12.3` parameter group family, so the output of `SHOW REPLICA HOSTS` doesn't include user and password information.

Diff

diff --git a/AmazonRDS/latest/UserGuide/MariaDB.Concepts.FeatureNonSupport.md b/AmazonRDS/latest/UserGuide/MariaDB.Concepts.FeatureNonSupport.md
index 0cf1fb5ad..3a40bc74d 100644
--- a//AmazonRDS/latest/UserGuide/MariaDB.Concepts.FeatureNonSupport.md
+++ b//AmazonRDS/latest/UserGuide/MariaDB.Concepts.FeatureNonSupport.md
@@ -38,0 +39,10 @@ You can enable encryption at rest for a MariaDB DB instance by following the ins
+  * New binary log implementation in InnoDB for MariaDB version 12.3
+
+RDS for MariaDB doesn't support the binary log implementation in InnoDB that MariaDB 12.3 introduces. The `binlog_storage_engine` parameter isn't available in the `mariadb12.3` parameter group family. For more information about this community feature, see [New binlog implementation in MariaDB 12.3](https://mariadb.org/new-binlog-implementation-in-mariadb-12-3/) on the MariaDB website.
+
+  * The `PATH` variable isn't available in the `mariadb12.3` parameter group family, and you can't set it as a global variable. You can still set `PATH` at the session level.
+
+  * Replication user information in the output of `SHOW REPLICA HOSTS`
+
+The `show_slave_auth_info` variable isn't available in the `mariadb12.3` parameter group family, so the output of `SHOW REPLICA HOSTS` doesn't include user and password information.
+