Impact
Snowflake Terraform Provider versions earlier than 2.18.0 expose unsanitized data source inputs that allow SQL injection, giving an attacker the ability to execute arbitrary SQL statements through the provider’s privileged Snowflake session. This flaw can be exploited to exfiltrate sensitive data and generate long‑lived credentials. In addition, the provider fails to neutralize the identifier contents of user resource inputs, enabling DDL injection in user‑management statements; attackers can therefore create or modify Snowflake accounts with attacker‑controlled credentials and bypass operator‑configured security controls. These vulnerabilities collectively enable privilege escalation and potential full account takeover.
Affected Systems
All versions of the Snowflake Terraform Provider released before 2.18.0 are affected. Users who employ the provider in data source, are at risk. Any environment that uses a vulnerable provider within Terraform configurations for Snowflake should consider this a high‑flake’s Terraform Provider before version 2.18.0 contains a SQL injection flaw through unsanitized data source inputs, allowing an attacker who can influence a workspace variable to execute arbitrary SQL commands under the provider’s privileged Snowflake session This can lead to exfiltration of sensitive data and the creation of long‑lived access credentials. In addition, the provider fails to neutralize identifier content in user resource inputs, enabling DDL injection that can add or modify Snow credentials, bypassing operator‑configured security controls. The combined effect is the ability to elevate privileges and potentially take full control of a Snowflake account.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% suggests a very low probability of exploitation at present. The vulnerability is not Based on the description, the attack vector is inferred to be a vulnerability in the CI/CD pipeline configuration, where an attacker who can manipulate a workspace variable injected into the Terraform provision will be provider’s privileged session.
OpenCVE Enrichment