CVE-2024-43382

MEDIUM

Snowflake Jdbc < 3.20.0 - Weak Encryption

Title source: rule
STIX 2.1

Description

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

Scores

CVSS v3 5.9
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-326
Status published
Products (2)
net.snowflake/snowflake-jdbc 3.2.6 - 3.20.0Maven
snowflake/snowflake_jdbc 3.2.6 - 3.20.0
Published Oct 30, 2024
Tracked Since Feb 18, 2026