CVE-2025-46614

LOW

Snowflake ODBC Driver <3.7.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.

Scores

CVSS v3 3.3
EPSS 0.0007
EPSS Percentile 22.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
Snowflake/Snowflake ODBC < 3.7.0
Published Apr 28, 2025
Tracked Since Feb 18, 2026