3.13.2
7 years ago
24 days ago
Known vulnerabilities in the snowflake-connector-python package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
snowflake-connector-python is a Snowflake Connector for Python Affected versions of this package are vulnerable to Incorrect Default Permissions when using Note: This is only exploitable for Linux systems. How to fix Incorrect Default Permissions? Upgrade | [2.3.7,3.13.1) |
snowflake-connector-python is a Snowflake Connector for Python Affected versions of this package are vulnerable to SQL Injection in the Note: Only a limited set of query types are not properly parameterized, and any SQL executed by the attacker will run in the context of the current session only. How to fix SQL Injection? Upgrade | [2.2.5,3.13.1) |
snowflake-connector-python is a Snowflake Connector for Python Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the insecure handling of serialization exceptions which is not supported for all exceptions. This is because The OCSP response cache uses pickle as the serialization format which is saved locally on the machine running the Connector. How to fix Deserialization of Untrusted Data? Upgrade | [2.7.12,3.13.1) |