First published: Wed Nov 09 2022(Updated: )
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method.
Credit: reefs@jfrog.com reefs@jfrog.com reefs@jfrog.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/snowflake-connector-python | <2.8.2 | 2.8.2 |
Snowflake Connector for Python | <2.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42965 has a severity rating that indicates a medium risk due to the potential for Denial of Service.
To fix CVE-2022-42965, upgrade the snowflake-connector-python package to version 2.8.2 or later.
CVE-2022-42965 is an exponential Regular Expression Denial of Service (ReDoS) vulnerability.
CVE-2022-42965 affects all versions of snowflake-connector-python up to, but not including, version 2.8.2.
The vulnerability in CVE-2022-42965 can be triggered in the get_file_transfer_type method when arbitrary input is supplied by an attacker.