Home » Database

AVID-2026-R1667

Description

The Snowflake Connector for Python uses insecure cache files permissions (CVE-2025-24795)

Details

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

Reason for inclusion in AVID: The report describes CVE-2025-24795 for Snowflake Connector for Python, which caches temporary credentials in a world-readable file on Linux, affecting versions 2.3.7–3.13.0 and fixed in 3.13.1. Snowflake Connector Python is a common data-access dependency used in AI/ML pipelines; insecure credential caching constitutes a security vulnerability with potential impact on the software supply chain for AI systems. It affects software components used to build/run AI systems and has clear remediation, making it relevant for AVID curation.

References

Affected or Relevant Artifacts

  • Developer: snowflakedb
  • Deployer: snowflakedb
  • Artifact Details:
TypeName
Systemsnowflake-connector-python

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score4.4
Base Severity🟠 Medium
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🟢 Low
Integrity Impact🟢 Low
Availability ImpactNONE

CWE

IDDescription
CWE-276CWE-276: Incorrect Default Permissions

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2025-01-29
  • Version: 0.3.3
  • AVID Entry