snowflake-connector-python is vulnerable to Insertion of Sensitive Information into Log File
65
Medium Risk
The Snowflake Python connector writes diagnostic logs that can include authentication tokens, OAuth access and refresh tokens, query result master keys (qrmk), pre signed cloud storage URLs, and SAML assertions. Log redaction misses some log paths and data types, so these secrets reach DEBUG logs, third party library logs (botocore, urllib3), and result batch metadata in cleartext. Anyone who can read those logs can recover valid credentials and decryption keys and reuse them against the Snowflake account or cloud storage. The fix enables default secret masking across connector and third party loggers and strips qrmk and chunk header values from result batch logs.
You are affected if you are using a version that falls within the vulnerable range and the connector's diagnostic logs are readable by other parties.
snowflake-connector-python is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 4.7.2.
Upgrade the snowflake-connector-python library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.