Description
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0122 | snowflake-connector-python vulnerable to SQL Injection in write_pandas |
Github GHSA |
GHSA-2vpq-fh52-j3wv | snowflake-connector-python vulnerable to SQL Injection in write_pandas |
References
History
Fri, 31 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. | |
| Title | Snowflake Connector for Python has an SQL Injection in write_pandas | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-31T16:54:16.113Z
Reserved: 2025-01-23T17:11:35.838Z
Link: CVE-2025-24793
Updated: 2025-01-31T16:54:10.684Z
Status : Undergoing Analysis
Published: 2025-01-29T21:15:21.270
Modified: 2025-01-29T21:15:21.270
Link: CVE-2025-24793
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA