Impact
Sensitive information such as authentication tokens, query‑result encryption keys, pre‑signed cloud‑storage URLs, and SAML assertions were written to diagnostic logs by the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers. The logging system’s redaction rules did not cover all log paths or data types, allowing secrets to appear in log files. An attacker who can read the log destination—including local files, log aggregation services, or CI/CD artifact stores—could capture valid credentials or decryption keys that remain active. The impact is limited to the lifetime of the secrets and the scope of the associated Snowflake account or cloud‑storage objects.
Affected Systems
Snowflake Connector for Python, Snowflake Go Driver, Snowflake JDBC Driver, Snowflake Node.js Driver, Snowflake ODBC Driver, Snowflake PHP PDO Driver.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog. Attackers must have read access to the logs; no special privileges are required beyond that. The exploit is feasible when logs are improperly protected, and the data can be used to compromise Snowflake accounts or cloud‑storage resources while the captured tokens or keys remain valid.
OpenCVE Enrichment