CVE-2026-3293
- EPSS 0.02%
- Veröffentlicht 27.02.2026 05:32:09
- Zuletzt bearbeitet 02.03.2026 15:17:33
A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executin...
CVE-2025-27496
- EPSS 0.03%
- Veröffentlicht 13.03.2025 19:15:52
- Zuletzt bearbeitet 22.08.2025 17:42:18
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Drive...
CVE-2025-24789
- EPSS 0.02%
- Veröffentlicht 29.01.2025 18:15:47
- Zuletzt bearbeitet 20.08.2025 18:18:54
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication me...
CVE-2025-24790
- EPSS 0.01%
- Veröffentlicht 29.01.2025 18:15:47
- Zuletzt bearbeitet 29.01.2025 18:15:47
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credentia...
CVE-2024-43382
- EPSS 0.21%
- Veröffentlicht 30.10.2024 21:15:14
- Zuletzt bearbeitet 20.08.2025 19:15:05
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.
CVE-2023-30535
- EPSS 2.09%
- Veröffentlicht 14.04.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:22
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up a maliciou...