PT-2025-18087 · Snowflake · Snowflake Jdbc Driver

CVE-2025-46614

·

Publicado

2025-04-28

·

Atualizado

2025-04-29

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Snowflake ODBC Driver versions prior to 3.7.0
Description The issue concerns the logging of sensitive information. In certain code paths, the whole SQL query was logged at the INFO level. This could potentially lead to the exposure of sensitive data.
Recommendations For Snowflake ODBC Driver versions prior to 3.7.0, update to version 3.7.0 or later to resolve the issue. As a temporary workaround, consider configuring the logging settings to exclude sensitive information, such as SQL queries, from being logged at the INFO level. Restrict access to log files to minimize the risk of sensitive data exposure.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-46614

Produtos afetados

Snowflake Jdbc Driver