#VU77308 Command Injection in snowflake-connector-nodejs - CVE-2023-34232
Published: June 14, 2023
snowflake-connector-nodejs
Snowflake
Description
The vulnerability allows a remote user to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation via single sign on (SSO) browser URL authentication. A remote user can trick user into opening a specially crafted data and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://github.com/snowflakedb/snowflake-connector-nodejs/pull/465
- https://github.com/snowflakedb/snowflake-connector-nodejs/commit/0c9622ae12cd7d627df404b73a783b4a5f60728a
- https://github.com/snowflakedb/snowflake-connector-nodejs/security/advisories/GHSA-h53w-7qw7-vh5c
- https://community.snowflake.com/s/article/Node-js-Driver-Release-Notes