Snowflake.Data
Snowflake Connector for .NET
Activity
- Latest release
- 1w ago
- Total releases
- 93
- Cadence
- ~29 days
- Last 12 months
- 12
Reach
- Stars
- 208
Details
- License
- Apache-2.0
- First release
- Aug 07, 2017
| Version | Released | |
|---|---|---|
6.1.0
minor
|
6.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
6.0.0
major
|
6.0.0
major
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.7.0
minor
|
5.7.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.6.0
minor
|
5.6.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.5.0
minor
|
5.5.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.4.1
patch
|
5.4.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.4.0
minor
|
5.4.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.3.0
minor
|
5.3.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.2.1
patch
|
5.2.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.2.0
minor
|
5.2.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.1.0
minor
|
5.1.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.0.0
major
|
5.0.0
major
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.8.0
minor
|
4.8.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.7.0
minor
|
4.7.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.6.0
minor
|
4.6.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.5.0
minor
|
4.5.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.4.1
patch
|
4.4.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.4.0
minor
1 CVE
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev |
4.4.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.3.0
minor
1 CVE
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev |
4.3.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
4.2.0
minor
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
4.2.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.1.0
minor
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
4.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.0.0
major
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
4.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
3.1.0
minor
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
3.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
3.0.0
major
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
3.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.2.0
minor
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.2.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.5
patch
2 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.1.5
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.4
patch
3 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.4
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.3
patch
3 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.2
patch
3 CVEs
CVE-2025-46326
GHSA-c82r-c9f7-f5mj
Apr 28, 2025
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET (“Connector”). When using the Easy Logging feature on Linux and macOS, the Connector didn’t correctly verify the permissions of the logging configuration file, potentially allowing an attacker with local access to overwrite the configuration and gain control over logging level and output location. This vulnerability affects Connector versions 2.1.2 through 4.4.0. Snowflake fixed the issue in version 4.4.1. Vulnerability DetailsWhen using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration from a user-provided file. On Linux and macOS, the Connector verifies that the configuration file can be written to only by its owner. That check was vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition and failed to verify that the file owner matches the user running the Connector. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. SolutionSnowflake released version 4.4.1 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.4.1. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.4.1
References
Updated Apr 29, 2025 · Source: OSV.dev
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.1.1
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.1.0
minor
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.0.25
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-51662
GHSA-hwcc-4cv8-cf3h
Dec 22, 2023
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
6.0
/ 10
Medium
Adjacent
High
High
None
Unchanged
High
High
Low
IssueSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in version 2.1.5. Attack ScenarioSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver. The vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats. SolutionOn December 18, 2023, Snowflake released version 2.1.5 of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to version 2.1.5. Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. AcknowledgementSnowflake would like to thank Timo Vink for reporting this vulnerability. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
Fixed in
2.1.5
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.0.25
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.0.24
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.24
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.23
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.23
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.22
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.22
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.21
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.21
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.20
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.20
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.19
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.19
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.18
patch
1 CVE
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev |
2.0.18
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.17
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.17
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.0.16
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.16
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.0.15
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.15
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.14
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.14
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.13
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.13
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.12
patch
2 CVEs
CVE-2025-24788
GHSA-2mqw-rq5m-8hc8
Jan 29, 2025
Snowflake.Data has weak temporary files permissions
5.0
/ 10
Medium
Local
Low
Low
Required
Unchanged
High
None
None
IssueSnowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. Vulnerability DetailsWhen downloading files from stages, the Snowflake Connector for .NET uses the OS temporary directory to save files before copying them to the destination directory. The files in the temporary directory, which are removed once the write to the destination directory concludes, have world-readable permissions on Linux and macOS. This could allow any user on the local machine to access them during their limited lifetime. SolutionSnowflake released version 4.3.0 of the Snowflake Connector for .NET, which fixes this issue. We recommend users upgrade to version 4.3.0. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
+ 9 more Show less
2.0.24
2.0.25
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
Fixed in
4.3.0
References
Updated Jan 29, 2025 · Source: OSV.dev
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.12
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.11
patch
1 CVE
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.11
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.10
patch
1 CVE
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.9
patch
1 CVE
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |
1.2.9
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.9
patch
1 CVE
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.8
patch
1 CVE
CVE-2023-34230
GHSA-223g-8w3x-98wr
Jun 09, 2023
Snowflake Connector .Net Command Injection
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
IssueSnowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. Impacted driver package:snowflake-connector-net Impacted version range:before Version 2.0.18 Attack ScenarioIn order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then tricked a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources. SolutionOn December 2nd, 2022, Snowflake merged a patch that fixed a command injection vulnerability in the Snowflake .NET driver via SSO URL authentication. The vulnerability affected the Snowflake .NET driver before Version 2.0.18. We strongly recommend upgrading to the latest driver version as soon as possible via the following resources: Snowflake .NET Driver. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
+ 42 more Show less
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.18
References Updated Sep 10, 2026 · Source: OSV.dev |