📦 Snowflake Connector

by Snowflake

🔍 What is Snowflake Connector?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24793

HIGH CVSS 7.0 Jan 29, 2025

The Snowflake Connector for Python contains a SQL injection vulnerability in the snowflake.connector.pandas_tools module. This allows attackers to execute arbitrary SQL commands on Snowflake databases...

CVE-2023-34230

HIGH CVSS 7.3 Jun 8, 2023

The Snowflake Connector for .NET is vulnerable to command injection via SSO URL authentication, allowing remote code execution if an attacker tricks a user into visiting a maliciously crafted connecti...

CVE-2023-34233

HIGH CVSS 8.8 Jun 8, 2023

The Snowflake Connector for Python versions before 3.0.2 are vulnerable to command injection through SSO browser URL authentication. An attacker can set up a malicious server and trick users into visi...

CVE-2025-24788

MEDIUM CVSS 5.0 Jan 29, 2025

The Snowflake Connector for .NET versions 2.0.12 through 4.2.0 on Linux and macOS temporarily store downloaded stage files in world-readable directories, allowing unauthorized local users on the same ...

CVE-2025-24794

MEDIUM CVSS 6.7 Jan 29, 2025

The Snowflake Connector for Python uses pickle for OCSP response cache serialization, allowing local attackers to execute arbitrary code via cache poisoning. This affects Python applications using vul...

CVE-2025-24791

MEDIUM CVSS 4.4 Jan 29, 2025

The snowflake-connector-nodejs driver has a vulnerability where file permission checks for temporary credential cache can be bypassed. An attacker with write access to the local cache directory could ...