Логотип exploitDog
bind:CVE-2024-49750
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49750

Количество 2

Количество 2

nvd логотип

CVE-2024-49750

больше 1 года назад

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the `passcode` parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. Snowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes the issue. In addition to upgrading, users should review their logs for any potentially sensitive information that may have been captured.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-5vvg-pvhp-hv2m

больше 1 года назад

The Snowflake Connector for Python stores sensitive data in logs

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-49750

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the `passcode` parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. Snowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes the issue. In addition to upgrading, users should review their logs for any potentially sensitive information that may have been captured.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-5vvg-pvhp-hv2m

The Snowflake Connector for Python stores sensitive data in logs

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу