PT-2023-22762 · Snowflake · Snowflake Jdbc Driver

Peter Mularien

·

Publicado

2023-04-14

·

Atualizado

2023-04-27

·

CVE-2023-30535

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Snowflake JDBC driver versions prior to 3.13.29
Description The Snowflake JDBC driver is affected by a command injection vulnerability via SSO URL authentication. An attacker can set up a malicious server that responds to the SSO URL with an attack payload. If the attacker tricks a user into visiting the maliciously crafted connection URL, the user's local machine will render the malicious payload, leading to remote code execution.
Recommendations For all versions prior to 3.13.29, upgrade the Snowflake JDBC driver to the latest version: 3.13.29. As a temporary workaround, consider restricting access to the SSO URL authentication mechanism until the patch is applied. Avoid using maliciously crafted connection URLs to minimize the risk of exploitation.

Exploit

Correção

Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30535
GHSA-4G3J-C4WG-6J7X

Produtos afetados

Snowflake Jdbc Driver