snowflakedb Vulnerabilities and Affected Products
Vulnerabilities associated with snowflake-hive-metastore-connector.
Products
Clear product- snowflake-connector-python5 vulnerabilities
- snowflake-jdbc5 vulnerabilities
- snowflake-connector-net4 vulnerabilities
- snowflake-connector-nodejs3 vulnerabilities
- gosnowflake2 vulnerabilities
- libsnowflakeclient2 vulnerabilities
- pdo_snowflake1 vulnerability
- snowflake-hive-metastore-connector1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-28851MEDIUM | Elevation of privilege in Snowflake Hive MetaStore Connector Helper scriptThe Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory, use the script to download content from a Microsoft domain to the local system and replace the valid content with malicious code. If the attacker then also had local access to the sa… CWE-269Mar 15, 2024 | CVSS4.0v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |