Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version. This vulnerability affects versions 3.2.3 through 3.21.0 on Windows. Snowflake fixed the issue in version 3.22.0.
{
"cwe_ids": [
"CWE-426"
]
}[
{
"id": "CVE-2025-24789-e1762ab4",
"target": {
"file": "src/main/java/net/snowflake/client/jdbc/SnowflakeDriver.java"
},
"digest": {
"line_hashes": [
"163462292315131043009619918423020661552",
"172755071904979632887942217402952396872",
"324038985784841644452231720853664589211",
"186511955661388583231338465135382544632"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ebb315c4a01b18e571cff086d67aff33def10400"
}
]