漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Snowflake JDBC uses insecure temporary credential cache file permissions
Vulnerability Description
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching is enabled, the Snowflake JDBC Driver will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 3.6.8 through 3.21.0. Snowflake fixed the issue in version 3.22.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
缺省权限不正确
Vulnerability Title
Snowflake JDBC 安全漏洞
Vulnerability Description
Snowflake JDBC是美国Snowflake公司的一个应用程序。提供了一个支持核心功能的 JDBC 类型 4 驱动程序,允许 Java 程序连接到 Snowflak。 Snowflake JDBC 3.22.0之前版本存在安全漏洞,该漏洞源于当启用临时凭据缓存时,会在本地可读文件中缓存临时凭据。
CVSS Information
N/A
Vulnerability Type
N/A