PT-2023-22762 · Snowflake · Snowflake Jdbc Driver
Peter Mularien
·
Published
2023-04-14
·
Updated
2023-04-27
·
CVE-2023-30535
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Snowflake JDBC driver versions prior to 3.13.29
Description
The Snowflake JDBC driver is affected by a command injection vulnerability via SSO URL authentication. An attacker can set up a malicious server that responds to the SSO URL with an attack payload. If the attacker tricks a user into visiting the maliciously crafted connection URL, the user's local machine will render the malicious payload, leading to remote code execution.
Recommendations
For all versions prior to 3.13.29, upgrade the Snowflake JDBC driver to the latest version: 3.13.29. As a temporary workaround, consider restricting access to the SSO URL authentication mechanism until the patch is applied. Avoid using maliciously crafted connection URLs to minimize the risk of exploitation.
Exploit
Fix
Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Jdbc Driver