Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Snowflake JDBC allows an untrusted search path on Windows
Vulnerability Description
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version. This vulnerability affects versions 3.2.3 through 3.21.0 on Windows. Snowflake fixed the issue in version 3.22.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不可信的搜索路径
Vulnerability Title
Snowflake JDBC 代码问题漏洞
Vulnerability Description
Snowflake JDBC是美国Snowflake公司的一个应用程序。提供了一个支持核心功能的 JDBC 类型 4 驱动程序,允许 Java 程序连接到 Snowflak。 Snowflake JDBC 3.22.0之前版本存在代码问题漏洞,该漏洞源于具有写权限的攻击者可以提升其权限。
CVSS Information
N/A
Vulnerability Type
N/A