Safety vulnerability ID: 51802
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Snowflake-connector-python 2.8.2 includes a fix for CVE-2022-42965: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method.
Latest version: 3.12.4
Snowflake Connector for Python
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method See CVE-2022-42965.
MISC:https://research.jfrog.com/vulnerabilities/snowflake-connector-python-redos-xray-257185/: https://research.jfrog.com/vulnerabilities/snowflake-connector-python-redos-xray-257185/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application