File Permissions Vulnerability in Snowflake NodeJS Driver on Linux
CVE-2025-24791

4.4MEDIUM

Key Information:

Vendor
CVE Published:
29 January 2025

What is CVE-2025-24791?

A vulnerability in the Snowflake NodeJS driver allows attackers to bypass file permissions checks related to the temporary credential cache. This issue arises when an attacker has write access to the local cache directory, potentially leading to unauthorized access to sensitive credentials. The vulnerability impacts versions 1.12.0 through 2.0.1 on Linux systems. Snowflake has addressed this vulnerability in the subsequent release, version 2.0.2.

Affected Version(s)

snowflake-connector-nodejs >= 1.12.0, < 2.0.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.