Vulnerability Description
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching is enabled, the Snowflake JDBC Driver will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 3.6.8 through 3.21.0. Snowflake fixed the issue in version 3.22.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snowflake | Snowflake Jdbc | >= 3.6.8, < 3.22.0 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://github.com/snowflakedb/snowflake-jdbc/commit/9e1a5acf12406b16c4780ca013fPatch
- https://github.com/snowflakedb/snowflake-jdbc/security/advisories/GHSA-33g6-495wVendor Advisory
FAQ
What is CVE-2025-24790?
CVE-2025-24790 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC ...
How severe is CVE-2025-24790?
CVE-2025-24790 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24790?
Check the references section above for vendor advisories and patch information. Affected products include: Snowflake Snowflake Jdbc, Linux Linux Kernel.