Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43382.json"
}[
{
"target": {
"file": "src/main/java/net/snowflake/client/jdbc/SnowflakeDriver.java"
},
"deprecated": false,
"id": "CVE-2024-43382-e7934dd2",
"signature_version": "v1",
"digest": {
"line_hashes": [
"87674454368960583278253932243093302631",
"252526441228695263399039897143504444639",
"124550780036735250839349245119655025324",
"168648994019949861507178290233732502679"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/21e98c74145461212ff3a47f3540bc1fd3026a5e"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-43382.json"
"2026-08-12T15:15:28Z"