VDB

CVE-2025-24793

CVE-2025-24793 PUBLISHED CVSS 7 HIGH

snowflake-connector-python vulnerable to SQL Injection in write_pandas

EPSS 0.19% · 40.5th percentile

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.19%
40.5th percentile

Affected Products

VendorProductVersions
snowflakedbsnowflake-connector-python>= 2.2.5, < 3.13.1
snowflakesnowflake_connector2.2.5
PyPIsnowflake-connector-python2.2.5

Timeline

  • Jan 21, 1970 Security Advisory
  • Jan 29, 2025 CVE Published
  • Jan 29, 2025 Coalition ESS Score
  • Jan 29, 2025 PoC Published
  • Jan 29, 2025 PoC Published
  • Jan 30, 2025 EPSS Score
  • Feb 14, 2025 EPSS Score
  • Mar 1, 2025 EPSS Score
  • Mar 16, 2025 EPSS Score
  • Mar 31, 2025 EPSS Score
  • Apr 15, 2025 EPSS Score
  • Apr 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›