PT-2025-12212 · Snowflake+3 · Snowflake+3

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8055

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vanna version 0.6.3
Description The issue allows unauthenticated remote users to read arbitrary local files on the victim server by exploiting exposed SQL queries through a Python Flask API. This is achieved via SQL injection in the Snowflake database, specifically in file staging operations using the PUT and COPY commands.
Recommendations For Vanna version 0.6.3, consider restricting access to the Snowflake database and limiting the use of the PUT and COPY commands until a patch is available. As a temporary workaround, review and modify the Python Flask API to prevent SQL injection attacks.

Fix

SQL injection

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8055

Affected Products

Python
Python Flask Api
Snowflake
Vanna