CVE-2025-27496

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Mar 13, 2025
CWE ID 532

Summary

CVE-2025-27496 is a vulnerability affecting Snowflake's JDBC driver in versions 3.0.13 to 3.23.0. When the logging level is set to DEBUG, the driver unintentionally logs the client-side encryption master key of the target stage during GET/PUT commands. This key alone does not grant access to sensitive data but can pose a security risk if intercepted. The issue was resolved in version 3.23.1, and Snowflake does not log the key server-side.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share