CVE-2025-24788

MEDIUM

Snowflake Connector < 4.3.0 - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0.

Scores

CVSS v3 5.0
EPSS 0.0015
EPSS Percentile 34.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (2)
nuget/Snowflake.Data 2.0.12 - 4.3.0NuGet
snowflake/snowflake_connector 2.0.12 - 4.3.0
Published Jan 29, 2025
Tracked Since Feb 18, 2026