GHSA-7hpq-3g6w-pvhf
HIGHCVE-2025-24789Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version.
- Affected
- >= 3.2.3, <= 3.21.0
- Fixed in
- 3.22.0
- Weakness
- CWE-426
- Published
- 2025-01-29
- Source
- github