Impact
The Snowflake provider for Apache Airflow fails to validate the `account` and `region` fields before inserting them into request URLs. An attacker who can edit a Snowflake connection can supply a value containing characters such as `/`, `?`, or `#`, causing the provider to build a request that redirects to an attacker‑controlled host while still sending a valid bearer token. This token is generated from private key, OAuth, or programmatic credentials and is included in the `Authorization: Bearer` header, effectively allowing the attacker to reuse it against the legitimate Snowflake service or to exfiltrate data. The result is uncontrolled disclosure of secret tokens and potential unauthorized access to the Snowflake account. This issue is classified as CWE-522.
Affected Systems
This issue, identified as CWE-522, affects deployments of the Apache Airflow Snowflake provider, specifically any installation using versions before 6.18.0 of `apache-airflow-providers-snowflake`. The vulnerability is exploitable in environments where users are granted permission to edit Snowflake connections but do not have read access to the stored credentials, allowing them to alter the `account` and `region` values. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
Risk and Exploitability
The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog. The CVSS score of 6.3 indicates a moderate impact, reflecting the potential for credential compromise without host compromise. The attacker can transmit a valid bearer token to an arbitrary host and replay it against the real Snowflake endpoint, providing unauthorized access. This requires only edit rights to a Snowflake connection, a permission that may be loosely enforced. Consequently, the overall risk to affected systems is high due to the ease of exploitation and the sensitivity of the exposed tokens.
OpenCVE Enrichment