LOW🇵🇱 Wersja polska

CVE-2025-46329

CVSS 3.3v3.1pub. 2025-04-29upd. 2025-05-09

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. This issue has been patched in version 2.2.0.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Snowflake Connector For C\/c\+\+

    APP
    Snowflake
    0.5.0 – 2.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-46330LOW3.3same product

libsnowflakeclient to Snowflake Connector dla C/C++. Wersje od 0.5.0 do 2.2.0 nieprawidłowo traktują żądania p...

CVE-2026-13749HIGH8.8PL ✓same vendor

RCE w Snowflake CLI — wstrzyknięcie kodu przez szablon Snowpark

CVE-2026-13744HIGH8.3PL ✓same vendor

SQL Injection w Snowflake CLI — niezamierzone wykonanie SQL przez złośliwe dane wejściowe

CVE-2025-24789HIGH7.8same vendor

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connec...

CVE-2025-24793HIGH7.0same vendor

The Snowflake Connector for Python provides an interface for developing Python applications that can connect t...