VYPR

NuGet package

snowflake.data

pkg:nuget/snowflake.data

Vulnerabilities (4)

  • CVE-2025-46326Apr 28, 2025
    affected >= 2.1.2, < 4.4.1fixed 4.4.1

    snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS, the Connector reads logging configuration f

  • CVE-2025-24788Jan 29, 2025
    affected >= 2.0.12, < 4.3.0fixed 4.3.0

    snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unautho

  • CVE-2023-51662Dec 22, 2023
    affected >= 2.0.25, < 2.1.5fixed 2.1.5

    The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (C

  • CVE-2023-34230Jun 8, 2023
    affected < 2.0.18fixed 2.0.18

    snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resou