snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directory. This vulnerability affects versions 1.12.0 through 2.0.1 on Linux. Snowflake fixed the issue in version 2.0.2.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NLinux Kernel
OSLinuxwszystkie wersjeSnowflake Connector
APPSnowflake1.12.0 – 2.0.2 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓ten sam produkt
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE przez YAML deserialization w IBM Aspera Faspex
CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection
CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓ten sam produkt
Command Injection w VMware Workspace One Access i Identity Manager