Vulnerabilities/

Snowflake NodeJS Driver vulnerable to Command Injection

Severity:
High

Description

Snowflake was informed via our bug bounty program of a command injection vulnerability in the Snowflake NodeJS driver via SSO browser URL authentication.

Recommendation

Update the snowflake-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
snowflake-sdk
Anything's wrong? Let us know Last updated on November 06, 2023

This issue is available in SmartScanner Professional

See Pricing