Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42965


An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method


Published

2022-11-09T20:15:10.820

Last Modified

2024-11-21T07:25:41.780

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-1333
  • Type: Primary
    CWE-1333

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application snowflake snowflake-connector-python < 2.8.2 Yes

References