PT-2026-51302 · Grafana · Snowflake Datasource Plugin+1
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana with Snowflake datasource plugin (affected versions not specified)
Description
The Snowflake datasource allows the use of GET and PUT commands. This enables any user with access to run queries against the data source to read and write arbitrary files between the local Grafana server and the connected Snowflake host.
Recommendations
Update the Snowflake datasource plugin.
Restrict access to the datasource to minimize the risk of exploitation.
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana
Snowflake Datasource Plugin