Command Injection in gosnowflake - CVE-2023-34231
Published: March 7, 2024
gosnowflake
Snowflake Computing (snowflakedb)
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists via single sign-on (SSO) browser URL authentication. A remote unauthenticated attacker can set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload, trick the victim into visiting the maliciously crafted connection URL and execute arbitrary code on the target system.