npm package
snowflake-sdk
pkg:npm/snowflake-sdk
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-46328 | — | >= 1.10.0, < 2.0.4 | 2.0.4 | Apr 28, 2025 | snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads logging configuration from | ||
| CVE-2025-24791 | — | >= 1.12.0, < 2.0.2 | 2.0.2 | Jan 29, 2025 | snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directo | ||
| CVE-2023-34232 | — | < 1.6.21 | 1.6.21 | Jun 8, 2023 | snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1) e |
- CVE-2025-46328Apr 28, 2025affected >= 1.10.0, < 2.0.4fixed 2.0.4
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads logging configuration from
- CVE-2025-24791Jan 29, 2025affected >= 1.12.0, < 2.0.2fixed 2.0.2
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directo
- CVE-2023-34232Jun 8, 2023affected < 1.6.21fixed 1.6.21
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1) e