Snowflake Connector
cpe:2.3:a:snowflake:snowflake_connector:*:*:*:*:*:*:*, +1 more
- < 4.7.1
A vulnerability exists in Snowflake Connector for Python in versions prior to 4.7.1, where improper TLS hostname verification may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections. This flaw could be exploited by intercepting or redirecting network traffic and presenting a certificate signed by any trusted Certificate Authority for any domain. As a result, the connector could accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires on-path traffic interception capabilities, such as ARP or DNS poisoning, a rogue access point, BGP hijacking, or through a malicious proxy or exit node. This vulnerability could have exposed credentials, query data, and staged file contents to interception and tampering, and may have allowed the attacker to execute arbitrary SQL within the context of the victim's connector session, limited by the privileges of the affected Snowflake role.
Exploitation of this vulnerability could have led to interception and tampering of data, including credentials and query information, and allowed for the execution of arbitrary SQL commands within the victim's connector session, based on the privileges of the Snowflake role in use.
Users are advised to upgrade to Snowflake Connector for Python version 4.7.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.