Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version. This vulnerability affects versions 3.2.3 through 3.21.0 on Windows. Snowflake fixed the issue in version 3.22.0.
{ "vanir_signatures": [ { "signature_version": "v1", "source": "https://github.com/snowflakedb/snowflake-jdbc/commit/4f01bb8f9b708c71e7a2111c87371dbfc1d53dd6", "deprecated": false, "id": "CVE-2025-24789-2d28c7fd", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "99699074694981551781387911331014660298", "153490221409874737269176603615242611930", "300090657058709668740202093872294213867", "85938648607449398519901793847835674715", "101520406633822450953099633071472614855", "102117943270625878051375214382687957320", "107217491475357868728036112443553019596", "13077181590231191622308214769401471836", "216888110030286258478481353643374478454", "158452615844006687287476508164377829324", "245807656535790414223160071499239377567", "178942967189889015507249758853720913693", "297153503046295235199993267981906617238", "334592464747736264696807599225836728038", "105834777571415904253780896376193086073", "63609182954769541472980690100511477777", "78210358694716845738786919833904235100", "163450970996774497134008252198793650204", "173647997530291740217359429465323489075", "192893631769023370080788693345609811127", "281236855596367116077451460382128134936", "217717282008116229527355030939455651635", "92776154069578780921090975422045032274", "210138913660295707146258681620638959503" ] }, "target": { "file": "src/main/java/net/snowflake/client/core/SessionUtilExternalBrowser.java" } }, { "signature_version": "v1", "source": "https://github.com/snowflakedb/snowflake-jdbc/commit/4f01bb8f9b708c71e7a2111c87371dbfc1d53dd6", "deprecated": false, "id": "CVE-2025-24789-345429f6", "signature_type": "Function", "digest": { "length": 660.0, "function_hash": "61201430305263953140884325533869509754" }, "target": { "file": "src/main/java/net/snowflake/client/core/SessionUtilExternalBrowser.java", "function": "openBrowser" } } ] }