VDB
CVE-2024-49750
CVE-2024-49750
PUBLISHED
CVSS 5.5 MEDIUM
The Snowflake Connector for Python stores sensitive data in logs
EPSS 0.20% · 10.1th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.20%
10.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| snowflakedb | snowflake-connector-python | < 3.12.3, < 3.12.3 |
| PyPI | snowflake-connector-python | 0, 0 |
| snowflake | snowflake_connector | 0, 0 |
Timeline
- Jan 21, 1970 Security Advisory
- Oct 24, 2024 CVE Published
- Oct 24, 2024 Coalition ESS Score
- Oct 25, 2024 EPSS Score
- Oct 25, 2024 Coalition ESS Score
- Oct 25, 2024 PoC Published
- Nov 6, 2024 Coalition ESS Score
- Nov 12, 2024 EPSS Score
- Dec 2, 2024 EPSS Score
- Dec 20, 2024 EPSS Score
- Jan 8, 2025 EPSS Score
- Jan 21, 2025 CVE Updated
References
- https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-5vvg-pvhp-hv2m url
- https://nvd.nist.gov/vuln/detail/CVE-2024-49750 advisory
- https://github.com/snowflakedb/snowflake-connector-python/commit/dbc9284a3c0382c131b971b35e8d6ab93c46f37a url
- https://github.com/pypa/advisory-database/tree/main/vulns/snowflake-connector-python/PYSEC-2024-191.yaml url
- https://github.com/snowflakedb/snowflake-connector-python package