CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-24788: Snowflake Connector for .NET has weak temporary files permissions

5.0 CVSS

Description

snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0.

Classification

CVE ID: CVE-2025-24788

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.0

Affected Products

Vendor: snowflakedb

Product: snowflake-connector-net

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.77% (scored less or equal to compared to others)

EPSS Date: 2025-02-28 (when was this score calculated)

References

https://github.com/snowflakedb/snowflake-connector-net/security/advisories/GHSA-2mqw-rq5m-8hc8
https://github.com/snowflakedb/snowflake-connector-net/commit/89d91e8316ca213c5d184bcf469ed93977a5edf9

Timeline