CVE-2025-46329

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. This issue has been patched in version 2.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowflake:connector_for_c\/c\+\+:*:*:*:*:*:*:*:*

History

09 May 2025, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 05:15

Updated : 2025-05-09 19:37


NVD link : CVE-2025-46329

Mitre link : CVE-2025-46329

CVE.ORG link : CVE-2025-46329


JSON object : View

Products Affected

snowflake

  • connector_for_c\/c\+\+
CWE
CWE-532

Insertion of Sensitive Information into Log File