Impact
The Snowflake Spark connector (spark-snowflake) contains multiple input validation flaws that can let an attacker disclose OAuth client credentials, run arbitrary SQL on the Snowflake account via the connector’s role, a shared Spark environment, or issuing runtime SET commands that inject SQL into the connector’s option map, all of which execute under the cluster admin’s JDBC credentials. An exploit can therefore lead to credential theft, unauthorized read or write access to Snowflake data, or privilege escalation against connected infrastructure.
Affected Systems
Snowflake: Snowflake Spark Connector versions earlier than 3.2.1 are affected. The vulnerability applies to any deployment of the connector that relies on earlier releases, regardless of the surrounding Spark configuration.
Risk and Exploitability
The vulnerability is scored CVSS 9.2, indicating a high severity of potential impact. The EPSS score is less than 1%, suggesting a low probability of widespread exploitation at the present time. The CISA KEV catalog does not diminish the risk to organizations that possess the affected connector. Attackers can exploit the weakness by submitting crafted OAuth URLs, injecting malicious data into ingestion pipelines, or injecting SQL via shared Spark environments. Successful exploitation can lead to the exfiltration of client credentials, execution of privileged SQL, or unauthorized access to data and services.
OpenCVE Enrichment