MEDIUM · 5.9

CVE-2024-43382

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provide...

Vulnerability Description

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SnowflakeSnowflake Jdbc>= 3.2.6, < 3.20.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-43382?

CVE-2024-43382 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provide...

How severe is CVE-2024-43382?

CVE-2024-43382 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-43382?

Check the references section above for vendor advisories and patch information. Affected products include: Snowflake Snowflake Jdbc.