PT-2023-3207 · Snowflake · Snowflake-Connector-Nodejs

Published

2023-05-18

·

Updated

2025-01-06

·

CVE-2023-34232

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions snowflake-connector-nodejs versions prior to 1.6.21
Description The issue is related to a command injection vulnerability via single sign on (SSO) browser URL authentication. An attacker would need to establish a malicious resource and redirect users to utilize it. The attacker could set up a malicious server that responds to the SSO URL with an attack payload, leading to remote code execution if a user visits the maliciously crafted connection URL. This can be mitigated through URL whitelisting and common anti-phishing resources.
Recommendations To resolve the issue, upgrade to version 1.6.21 or later. As a temporary workaround, consider implementing URL whitelisting and using common anti-phishing resources to minimize the risk of exploitation. Restrict access to the SSO URL authentication feature until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-03327
CVE-2023-34232
GHSA-H53W-7QW7-VH5C

Affected Products

Snowflake-Connector-Nodejs