AVID-2026-R1667
Description
The Snowflake Connector for Python uses insecure cache files permissions (CVE-2025-24795)
Details
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.
Reason for inclusion in AVID: The report describes CVE-2025-24795 for Snowflake Connector for Python, which caches temporary credentials in a world-readable file on Linux, affecting versions 2.3.7–3.13.0 and fixed in 3.13.1. Snowflake Connector Python is a common data-access dependency used in AI/ML pipelines; insecure credential caching constitutes a security vulnerability with potential impact on the software supply chain for AI systems. It affects software components used to build/run AI systems and has clear remediation, making it relevant for AVID curation.
References
- NVD entry
- https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-r2x6-cjg7-8r43
- https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af
Affected or Relevant Artifacts
- Developer: snowflakedb
- Deployer: snowflakedb
- Artifact Details:
| Type | Name |
|---|---|
| System | snowflake-connector-python |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| Base Score | 4.4 |
| Base Severity | 🟠 Medium |
| Attack Vector | LOCAL |
| Attack Complexity | 🟢 Low |
| Privileges Required | 🟢 Low |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | 🟢 Low |
| Integrity Impact | 🟢 Low |
| Availability Impact | NONE |
CWE
| ID | Description |
|---|---|
| CWE-276 | CWE-276: Incorrect Default Permissions |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2025-01-29
- Version: 0.3.3
- AVID Entry