CVE-2025-24793
CVSS 3.1 Score 7 of 10 (high)
Details
Published Jan 29, 2025
CWE ID 89
Summary
CVE-2025-24793: A vulnerability was discovered in the Snowflake Connector for Python, specifically in the snowflake.connector.pandas_tools module. This issue allows SQL injection attacks due to insufficient input validation. Versions 2.2.5 through 3.13.0 are affected, and Snowflake addressed the vulnerability in version 3.13.1. Users of the Snowflake Connector for Python are encouraged to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share