PT-2025-12212 · Snowflake+3 · Snowflake+3

Publicado

2025-03-20

·

Atualizado

2025-03-20

·

CVE-2024-8055

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vanna version 0.6.3
Description The issue allows unauthenticated remote users to read arbitrary local files on the victim server by exploiting exposed SQL queries through a Python Flask API. This is achieved via SQL injection in the Snowflake database, specifically in file staging operations using the PUT and COPY commands.
Recommendations For Vanna version 0.6.3, consider restricting access to the Snowflake database and limiting the use of the PUT and COPY commands until a patch is available. As a temporary workaround, review and modify the Python Flask API to prevent SQL injection attacks.

Correção

SQL injection

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-8055

Produtos afetados

Python
Python Flask Api
Snowflake
Vanna