Snowflake CLI 在 3.27.0 之前的版本存在输入验证不当的漏洞,导致未经净化的、由用户控制的值被直接插入到以多语句查询形式执行的 SQL 字符串中。攻击者若能提供恶意的项目配置文件或构造特定的命令行输入,可诱使 Snowflake CLI 在受害者的 Snowflake 会话及其当前激活角色上下文中执行由攻击者控制的 SQL 语句。 成功利用该漏洞需满足以下任一条件: 对某个项目的仓库具有写入权限或 Pull Request 提交权限,且该仓库的 CI/CD 管道以具备较高权限的服务账户角色运行 S
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Snowflake | Snowflake CLI | 0 ~ 3.27.0 | - |
|
| Snowflake | Snowflake CLI | 0 ~ 3.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet