PT-2023-24756 · Snowflake · Snowflake-Connector-Net

·

CVE-2023-34230

·

Published

2023-06-08

·

Updated

2025-11-21

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions snowflake-connector-net versions prior to 2.0.18
Description The issue is related to command injection via SSO URL authentication. An attacker would need to establish a malicious resource and redirect users to utilize it. The attacker could set up a malicious server that responds to the SSO URL with an attack payload. If the attacker tricks a user into visiting the maliciously crafted connection URL, the user’s local machine would render the malicious payload, leading to a remote code execution. This attack scenario can be mitigated through URL whitelisting as well as common anti-phishing resources.
Recommendations For versions prior to 2.0.18, upgrade to version 2.0.18 or later to fix the issue. As a temporary workaround, consider implementing URL whitelisting and using common anti-phishing resources to minimize the risk of exploitation. Restrict access to the SSO URL authentication feature until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-34230
GHSA-223G-8W3X-98WR

Affected Products

Snowflake-Connector-Net