CVE-2022-42965 is an exponential Regular Expression Denial of Service (ReDoS) vulnerability impacting the snowflake-connector-python PyPI package. An unauthenticated attacker can trigger this by supplying arbitrary input to the undocumented get_file_transfer_type method. Rated 7.5 HIGH (CVSS:3.1), this vulnerability allows a remote attacker to achieve a denial of service with low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.2CPE matchmatch criteria | cpe:2.3:a:snowflake:snowflake_connector:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.