CVE-2023-30535 is a command injection vulnerability in the Snowflake JDBC driver, affecting versions prior to 3.13.29. An attacker could exploit this by setting up a malicious server and tricking a user into visiting a specially crafted connection URL, leading to remote code execution on the user's machine. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity but requiring user interaction, resulting in high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness. Users are strongly advised to upgrade to Snowflake JDBC driver version 3.13.29 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13.29CPE matchmatch criteria | cpe:2.3:a:snowflake:snowflake_jdbc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.