PT-2023-24757 · Snowflake · Snowflake Connector For Python

Publicado

2023-06-08

·

Atualizado

2023-06-16

·

CVE-2023-34233

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Snowflake Connector for Python versions prior to 3.0.2
Description The issue concerns a command injection vulnerability via single sign-on (SSO) browser URL authentication. An attacker would need to establish a malicious resource and redirect users to it. The attacker could set up a malicious server that responds to the SSO URL with an attack payload. If a user visits the maliciously crafted connection URL, their local machine would render the malicious payload, leading to remote code execution. This can be mitigated through URL whitelisting and common anti-phishing resources.
Recommendations For versions prior to 3.0.2, upgrade to version 3.0.2 as soon as possible to fix the command injection vulnerability. As a temporary workaround, consider implementing URL whitelisting and utilizing common anti-phishing resources to minimize the risk of exploitation.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34233
GHSA-5W5M-PFW9-C8FP
PYSEC-2023-88

Produtos afetados

Snowflake Connector For Python