Showing 1 vulnerability on this page for snowflake-hive-metastore-connector

Signals CISA KEV Ransomware Nuclei
snowflakedb vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Elevation of privilege in Snowflake Hive MetaStore Connector Helper script

The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory, use the script to download content from a Microsoft domain to the local system and replace the valid content with malicious code. If the attacker then also had local access to the sa

CWE-269Mar 15, 2024
CVSS4.0v3.1EPSS0.252%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX