PT-2025-12212 · Snowflake+3 · Snowflake+3
Publicado
2025-03-20
·
Atualizado
2025-03-20
·
CVE-2024-8055
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vanna version 0.6.3
Description
The issue allows unauthenticated remote users to read arbitrary local files on the victim server by exploiting exposed SQL queries through a Python Flask API. This is achieved via SQL injection in the Snowflake database, specifically in file staging operations using the
PUT and COPY commands.Recommendations
For Vanna version 0.6.3, consider restricting access to the Snowflake database and limiting the use of the
PUT and COPY commands until a patch is available. As a temporary workaround, review and modify the Python Flask API to prevent SQL injection attacks.Correção
SQL injection
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Python
Python Flask Api
Snowflake
Vanna