CVE-2025-46329
Snowflake Connector for C/C++ inserts client-side encryption key in DEBUG logs
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.3EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. This issue has been patched in version 2.2.0.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
snowflakedb · libsnowflakeclientWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →