snowflake-connector-python is vulnerable to Insertion of Sensitive Information into Log File
35
Low Risk
Connector logging writes sensitive values in clear text, including raw SQL statement text, request Authorization headers, OAuth access and refresh tokens, one-time passcodes, and the per-result qrmk result-encryption key. These values appear in DEBUG records and some ERROR records emitted regardless of log level, and are exposed to anyone able to read the application logs. No secret masking is applied to these paths by default, so the values persist in downstream log sinks. The fix masks SQL and secret patterns, logs only the presence of the qrmk and non-sensitive chunk-header metadata, and installs the masking filter on the connector loggers by default.
You are affected if you are using a version that falls within the vulnerable range and connector logs are readable by parties who should not see the credentials, tokens, keys, or SQL they contain.
snowflake-connector-python is vulnerable to Insertion of Sensitive Information into Log File in versions 2.4.2 - 4.7.2.
Upgrade the snowflake-connector-python library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.