Intel

AIKIDO-2024-10018

snowflake-connector-python is vulnerable to Debug Messages Revealing Unnecessary Information

Debug Messages Revealing Unnecessary Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 10, 2024

20

Low Risk

This Affects:

pythonsnowflake-connector-python
1.8.7 - 3.7.1
Fixed in 3.8.1
Are you affected? Scan for Free

TL;DR

In cases where truncated passwords are shorter than 8 characters, they may be exposed in the log files.

Who does this affect?

You are affected if you are using a version of this package = 3.7.1.

Background info

snowflake-connector-python is vulnerable to Debug Messages Revealing Unnecessary Information in versions 1.8.7 - 3.7.1.

How to fix this

Upgrade the snowflake-connector-python library to the patch version.