Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version. This vulnerability affects versions 3.2.3 through 3.21.0 on Windows. Snowflake fixed the issue in version 3.22.0.
{
"cwe_ids": [
"CWE-426"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24789.json",
"cna_assigner": "GitHub_M"
}"2026-08-12T15:13:21Z"
[
{
"id": "CVE-2025-24789-2d28c7fd",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"99699074694981551781387911331014660298",
"153490221409874737269176603615242611930",
"300090657058709668740202093872294213867",
"85938648607449398519901793847835674715",
"101520406633822450953099633071472614855",
"102117943270625878051375214382687957320",
"107217491475357868728036112443553019596",
"13077181590231191622308214769401471836",
"216888110030286258478481353643374478454",
"158452615844006687287476508164377829324",
"245807656535790414223160071499239377567",
"178942967189889015507249758853720913693",
"297153503046295235199993267981906617238",
"334592464747736264696807599225836728038",
"105834777571415904253780896376193086073",
"63609182954769541472980690100511477777",
"78210358694716845738786919833904235100",
"163450970996774497134008252198793650204",
"173647997530291740217359429465323489075",
"192893631769023370080788693345609811127",
"281236855596367116077451460382128134936",
"217717282008116229527355030939455651635",
"92776154069578780921090975422045032274",
"210138913660295707146258681620638959503"
]
},
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/4f01bb8f9b708c71e7a2111c87371dbfc1d53dd6",
"target": {
"file": "src/main/java/net/snowflake/client/core/SessionUtilExternalBrowser.java"
}
},
{
"id": "CVE-2025-24789-345429f6",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 660.0,
"function_hash": "61201430305263953140884325533869509754"
},
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/4f01bb8f9b708c71e7a2111c87371dbfc1d53dd6",
"target": {
"function": "openBrowser",
"file": "src/main/java/net/snowflake/client/core/SessionUtilExternalBrowser.java"
}
},
{
"id": "CVE-2025-24789-e1762ab4",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"163462292315131043009619918423020661552",
"172755071904979632887942217402952396872",
"324038985784841644452231720853664589211",
"186511955661388583231338465135382544632"
]
},
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ebb315c4a01b18e571cff086d67aff33def10400",
"target": {
"file": "src/main/java/net/snowflake/client/jdbc/SnowflakeDriver.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24789.json"