First published: Mon Apr 28 2025(Updated: )
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Snowflake ODBC Driver | <3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46614 is considered a high-severity vulnerability due to the potential exposure of sensitive information in log files.
To fix CVE-2025-46614, you should upgrade the Snowflake ODBC Driver to version 3.7.0 or later.
CVE-2025-46614 allows the Snowflake ODBC Driver to log entire SQL queries, which may include sensitive user data.
Users of Snowflake ODBC Driver versions prior to 3.7.0 are affected by CVE-2025-46614.
CVE-2025-46614 does not appear to have a specific remote exploitation vector, but sensitive information exposure can lead to indirect attacks.