Snowflake · Snowflake Jdbc Driver · CVE-2023-30535
**Name of the Vulnerable Software and Affected Versions**
Snowflake JDBC driver versions prior to 3.13.29
**Description**
The Snowflake JDBC driver is affected by a command injection vulnerability via SSO URL authentication. An attacker can set up a malicious server that responds to the SSO URL with an attack payload. If the attacker tricks a user into visiting the maliciously crafted connection URL, the user's local machine will render the malicious payload, leading to remote code execution.
**Recommendations**
For all versions prior to 3.13.29, upgrade the Snowflake JDBC driver to the latest version: 3.13.29. As a temporary workaround, consider restricting access to the SSO URL authentication mechanism until the patch is applied. Avoid using maliciously crafted connection URLs to minimize the risk of exploitation.