Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.

Subscriptions

Vendors Products
Snowflake Subscribe
Snowflake Jdbc Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-6404 Snowflake JDBC Driver client-side encryption key in DEBUG logs
Github GHSA Github GHSA GHSA-q298-375f-5q63 Snowflake JDBC Driver client-side encryption key in DEBUG logs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Aug 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Snowflake
Snowflake snowflake Jdbc
CPEs cpe:2.3:a:snowflake:snowflake_jdbc:*:*:*:*:*:*:*:*
Vendors & Products Snowflake
Snowflake snowflake Jdbc

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00011}

epss

{'score': 0.00014}


Thu, 13 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Description Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.
Title Snowflake JDBC Driver client-side encryption key in DEBUG logs
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-13T19:51:10.678Z

Reserved: 2025-02-26T18:11:52.304Z

Link: CVE-2025-27496

cve-icon Vulnrichment

Updated: 2025-03-13T19:50:55.348Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-13T19:15:52.050

Modified: 2025-08-22T17:42:18.167

Link: CVE-2025-27496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses