PT-2025-18087 · Snowflake · Snowflake Jdbc Driver

Published

2025-04-28

·

Updated

2025-04-29

·

CVE-2025-46614

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Snowflake ODBC Driver versions prior to 3.7.0
Description The issue concerns the logging of sensitive information. In certain code paths, the whole SQL query was logged at the INFO level. This could potentially lead to the exposure of sensitive data.
Recommendations For Snowflake ODBC Driver versions prior to 3.7.0, update to version 3.7.0 or later to resolve the issue. As a temporary workaround, consider configuring the logging settings to exclude sensitive information, such as SQL queries, from being logged at the INFO level. Restrict access to log files to minimize the risk of sensitive data exposure.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-46614

Affected Products

Snowflake Jdbc Driver