Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Snowflake CLI Sensitive Credential Exposure Through Debug Logging
Vulnerability Description
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker could exploit this by obtaining read access to the affected user's local log files, causing credentials such as passwords, tokens, or private key material to be exposed without additional application-level safeguards. Successful exploitation requires credentials to be present in the affected connection context and the resulting logs to be accessible from the local environment. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Snowflake CLI 日志信息泄露漏洞
Vulnerability Description
Snowflake CLI是美国Snowflake公司的一个命令行工具,用于管理云计算环境中的数据仓库任务。 Snowflake CLI 3.19之前版本存在日志信息泄露漏洞,该漏洞源于敏感信息插入日志文件,导致明文凭据写入持久本地调试日志,攻击者可通过获取受影响用户的本地日志文件读取权限,导致密码、令牌或私钥材料等凭据泄露。
CVSS Information
N/A
Vulnerability Type
N/A