Snowflake Connector for Python OCSP Response Cache Deserialization Vulnerability Leading to Privilege Escalation

Vulnerability

A vulnerability exists in the Snowflake Connector for Python, specifically in versions 2.7.12 through 3.13.0, where the OCSP response cache is serialized using pickle. This serialization method can be exploited to achieve local privilege escalation, particularly if an attacker can write to the OCSP response cache file.

Impact

Exploitation of this vulnerability could result in local privilege escalation, allowing an attacker to gain elevated rights on the machine running the Snowflake Connector for Python.

Reproduction

The vulnerability can be reproduced by using the Snowflake Connector for Python versions 2.7.12 to 3.13.0. The OCSP response cache will be serialized with pickle, creating a risk of privilege escalation if the cache file is writable.

Remediation

Users are advised to upgrade to version 3.13.1 of the Snowflake Connector for Python, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
7.5
exploitability
3.8
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.