Snowflake Connector for Python
cpe:2.3:a:snowflake:snowflake-connector-python:*:*:*:*:*:*:*
- >= 2.7.12, <= 3.13.0
A vulnerability exists in the Snowflake Connector for Python, specifically in versions 2.7.12 through 3.13.0, where the OCSP response cache is serialized using pickle. This serialization method can be exploited to achieve local privilege escalation, particularly if an attacker can write to the OCSP response cache file.
Exploitation of this vulnerability could result in local privilege escalation, allowing an attacker to gain elevated rights on the machine running the Snowflake Connector for Python.
The vulnerability can be reproduced by using the Snowflake Connector for Python versions 2.7.12 to 3.13.0. The OCSP response cache will be serialized with pickle, creating a risk of privilege escalation if the cache file is writable.
Users are advised to upgrade to version 3.13.1 of the Snowflake Connector for Python, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.