Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-46328

Опубликовано: 28 апр. 2025
Источник: nvd
CVSS3: 3.3
CVSS3: 7
EPSS Низкий

Описание

snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads logging configuration from a user-provided file. On Linux and macOS the Driver verifies that the configuration file can be written to only by its owner. That check was vulnerable to a TOCTOU race condition and failed to verify that the file owner matches the user running the Driver. This could allow a local attacker with write access to the configuration file or the directory containing it to overwrite the configuration and gain control over logging level and output location. This issue has been patched in version 2.0.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:snowflake:snowflake_connector:*:*:*:*:*:node.js:*:*
Версия от 1.10.0 (включая) до 2.0.4 (исключая)

EPSS

Процентиль: 0%
0.00005
Низкий

3.3 Low

CVSS3

7 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 3.3
github
9 месяцев назад

NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file

EPSS

Процентиль: 0%
0.00005
Низкий

3.3 Low

CVSS3

7 High

CVSS3

Дефекты

CWE-367