CVE-2025-24795

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24795
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24795.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24795
Aliases
Related
Published
2025-01-29T20:30:18.062Z
Modified
2025-12-05T08:52:50.290363Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
The Snowflake Connector for Python uses insecure cache files permissions
Details

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-276"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24795.json"
}
References

Affected packages

Git / github.com/snowflakedb/snowflake-connector-python

Affected ranges

Type
GIT
Repo
https://github.com/snowflakedb/snowflake-connector-python
Events