AWS athena: Athena ODBC v2 2.4.0.0: SQL injection, TLS, and auth fixes
Summary
Adds release notes for Athena ODBC v2 driver 2.4.0.0, including a fix that escapes single quotes in SQLBindParameter values (preventing bound values from being interpreted as query text), a fix for TLS certificate verification on Linux (CA bundle resolution, CURL_CA_BUNDLE/SSL_CERT_FILE), removal of SigV4 signing on SSO OIDC RegisterClient/CreateToken/GetRoleCredentials requests, correct NULL parameter handling, S3 result-fetch retry/credential refresh, proxy DNS handling, and a new UserAgentPrivacyMode connection parameter.
Security assessment
The changed line explicitly states that bound parameter values containing a quotation mark were previously interpreted as part of the query and are now escaped as typed SQL literals, which is a concrete SQL-injection/query-tampering fix. The same release also fixes TLS certificate verification on Linux (CA bundle resolution honoring CURL_CA_BUNDLE/SSL_CERT_FILE), stops SigV4-signing SSO OIDC RegisterClient/CreateToken/GetRoleCredentials requests, and adds a UserAgentPrivacyMode parameter, all of which are security-relevant hardening.
Evidence
* Fixed an issue in how the driver formats parameter values that you bind with `SQLBindParameter`. The driver now sends each value as a typed SQL literal and escapes single quotation marks within it, so a value that contains a quotation mark is no longer interpreted as part of the query. String parameters are no longer wrapped in `CAST(`value` AS CHAR(`n`))`. A value that contains an embedded null character is now rejected with `SQL_ERROR`. This behavior matches the Amazon Athena JDBC 3.x driver.
Diff
diff --git a/athena/latest/ug/odbc-v2-driver-release-notes.md b/athena/latest/ug/odbc-v2-driver-release-notes.md index 54ec52b8f..6da7964a5 100644 --- a//athena/latest/ug/odbc-v2-driver-release-notes.md +++ b//athena/latest/ug/odbc-v2-driver-release-notes.md @@ -7 +7 @@ -2.2.0.12.2.0.02.1.0.02.0.6.02.0.5.12.0.5.02.0.4.02.0.3.02.0.2.22.0.2.12.0.2.02.0.1.12.0.1.0 +2.4.0.02.2.0.12.2.0.02.1.0.02.0.6.02.0.5.12.0.5.02.0.4.02.0.3.02.0.2.22.0.2.12.0.2.02.0.1.12.0.1.0 @@ -12,0 +13,53 @@ These release notes provide details of enhancements, features, known issues, and +## 2.4.0.0 + +Released 2026-09-28 + +This release includes changes made since version 2.2.0.1. + +### Fixes + + * Fixed an issue that caused `SQLTables` and `SQLColumns` to omit tables at approximately position 200 and later within a schema. This happened when the driver received two consecutive empty pages while paginating metadata results. + + * Fixed an issue that caused empty string filter patterns from ADO.NET applications such as Power BI to return zero rows instead of all rows. The driver now treats an empty string pattern as no restriction, which matches all values. + + * Fixed an issue that caused `SQLColumns` to fail on column types that the driver does not recognize, such as `uuid` or `json`. These columns are now reported with the SQL type `VARCHAR`. The `TYPE_NAME` column continues to report the Athena type name. + + * Fixed an issue that caused connections that use the `SageMakerBrowserIdc` authentication plugin to stop responding until the identity provider response timeout elapsed when the `SSOOIDCEndpointOverride` parameter was set. + + * Fixed an issue that caused the driver to ignore the `SSOEndpointOverride` parameter for connections that use the `BrowserSSOOIDC` authentication plugin. + + * Fixed an issue that caused connections through a proxy server to fail with Domain Name System (DNS) resolution errors when the proxy performs DNS resolution. HTTP clients that the AWS SDK creates internally now use the driver's configured proxy settings. + + * Fixed an issue that caused Transport Layer Security (TLS) certificate verification to fail on Linux when the `TrustedCerts` parameter was not set. The driver now locates the CA bundle at runtime and honors the `CURL_CA_BUNDLE` and `SSL_CERT_FILE` environment variables. The resolved CA bundle is also applied to HTTP clients that the AWS SDK creates internally. + + * Fixed an issue that prevented the Linux driver from installing on distributions with glibc 2.28, including Red Hat Enterprise Linux 8 and Rocky Linux 8. The Linux driver now builds against a glibc 2.28 baseline and requires glibc 2.28 or later. On SUSE Linux Enterprise Server 15, use SP3 or later, which provides a compatible glibc version. + + * Fixed an issue that could cause the Linux driver to crash when a host application that had already loaded a different OpenSSL library, such as an R environment, loaded the driver. The driver now restricts its exported symbols to the ODBC API so that its bundled cryptography library is not affected by the host application's OpenSSL. + + * Fixed an issue that caused the driver to send requests to identity providers without a `User-Agent` header. + +###### Action required: User-Agent header change + +This release changes the driver `User-Agent` header for Athena, AWS Glue, Amazon S3, and supported identity provider requests. Windows Integrated Authentication continues to use a browser `User-Agent`. + +If you match the driver's `User-Agent` in IAM `aws:UserAgent` policy conditions, log filters, or identity provider sign-on rules, update the pattern to `*lib/AmazonAthenaODBC#*`. This pattern does not match Windows Integrated Authentication requests. + + * Fixed an issue that could cause `SageMakerBrowserIdc` and `BrowserSSOOIDC` authentication to fail on hosts that have ambient AWS credentials. The driver no longer SigV4-signs the SSO OIDC `RegisterClient` and `CreateToken` requests used by these plugins. `BrowserSSOOIDC` also no longer SigV4-signs SSO `GetRoleCredentials` requests. `CreateTokenWithIAM` requests remain SigV4-signed. + + * Fixed issues that could cause transient Amazon S3 result-fetch failures to return partial results. The issues could also cause the driver to stop responding when the stream ended with an unterminated quoted multiline CSV record. The driver now makes up to three attempts per block. Each attempt fetches the byte range from the current stream offset. Between attempts, the driver recreates the Amazon S3 client so that the retry can use refreshed credentials. Errors that are not transient, such as access denied, are returned without a retry. If the result file ends prematurely, applications now receive `SQL_ERROR` instead of partial rows followed by `SQL_NO_DATA`. + + * Fixed an issue in how the driver formats parameter values that you bind with `SQLBindParameter`. The driver now sends each value as a typed SQL literal and escapes single quotation marks within it, so a value that contains a quotation mark is no longer interpreted as part of the query. String parameters are no longer wrapped in `CAST(`value` AS CHAR(`n`))`. A value that contains an embedded null character is now rejected with `SQL_ERROR`. This behavior matches the Amazon Athena JDBC 3.x driver. + +###### Action required: trailing spaces in bound string parameters + +Because the driver no longer sends string parameters as `CHAR` values, comparisons against them no longer ignore trailing spaces. A predicate such as `WHERE `column` = ?` that previously matched rows whose column values differ from the bound value only in trailing spaces now returns fewer rows. If your application depends on the earlier behavior, trim both sides of the comparison, for example `WHERE rtrim(`column`) = rtrim(?)`. + + * Fixed an issue that caused parameters bound as null with `SQL_NULL_DATA` to be sent as values instead of as `NULL`. A null `SQL_REAL`, `SQL_FLOAT`, or `SQL_DOUBLE` parameter was sent as `0.0`. A null parameter of any other type was sent as the string `NULL`. For string parameters, this value matched rows that contain the text `NULL`. Queries that bind null date and time parameters failed. The driver now sends `NULL` for a null parameter of any type. + + * Added the optional `UserAgentPrivacyMode` connection parameter. Set this parameter to `1` to omit runtime environment metadata from the `User-Agent` header on identity provider requests, while retaining `lib/AmazonAthenaODBC#<version>`. Requests to AWS services, including Athena, AWS Glue, and Amazon S3, always include the full `User-Agent` header. + + + + +To download the new ODBC v2 driver, see [ODBC 2.x driver download](./odbc-v2-driver.html#odbc-v2-driver-download). For connection information, see [Amazon Athena ODBC 2.x](./odbc-v2-driver.html). +