The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0179 | snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache |
Github GHSA |
GHSA-m4f6-vcj4-w5mx | snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. | |
| Title | The Snowflake Connector for Python uses insecure deserialization of the OCSP response cache | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-31T16:53:18.367Z
Reserved: 2025-01-23T17:11:35.838Z
Link: CVE-2025-24794
Updated: 2025-01-31T16:53:12.551Z
Status : Undergoing Analysis
Published: 2025-01-29T21:15:21.397
Modified: 2025-01-29T21:15:21.397
Link: CVE-2025-24794
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA