snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 29 Jan 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0. | |
Title | Snowflake Connector for .NET has weak temporary files permissions | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-31T16:55:14.494Z
Reserved: 2025-01-23T17:11:35.836Z
Link: CVE-2025-24788

Updated: 2025-01-31T16:55:09.668Z

Status : Received
Published: 2025-01-29T21:15:21.140
Modified: 2025-01-29T21:15:21.140
Link: CVE-2025-24788

No data.