Snowflake Vulnerabilities and Affected Products
Vulnerabilities associated with Snowflake ODBC.
Products
Clear product- Snowflake CLI7 vulnerabilities
- Cortex Code CLI1 vulnerability
- Snowflake Connector for Python1 vulnerability
- Snowflake libsnowflakeclient1 vulnerability
- Snowflake ODBC1 vulnerability
- Snowflake ODBC Driver1 vulnerability
- Snowflake PHP PDO Driver1 vulnerability
- Snowflake Python APIs1 vulnerability
- Snowflake Spark Connector1 vulnerability
- Snowflake SQLAlchemy1 vulnerability
- snowflake_jdbc1 vulnerability
- Snowpark Python SDK1 vulnerability
- Terraform Provider for Snowflake1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File. CWE-532Apr 28, 2025 | CVSS3.3v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |