Product
Unauthenticated attackers can achieve arbitrary SQL execution in PyAthena versions prior to 3.35.4 by exploiting improper quote-escaping within the DefaultParameterFormatter.format() function.