CVE FIX - upgrade snowflake jdbc driver to 3.21.0

Assignee

Reporter

Sprint

Description

CVE-2024-43382

  • cvssV3: MEDIUM, score: 5.9

  • snowflake-jdbc@3.13.29

  • please, check if this is relevant to CloverDX

 Standard Output

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

 Standard Error

location: /data/jenkins/.gradle/caches/modules-2/files-2.1/net.snowflake/snowflake-jdbc/3.13.29/44fc3b00b7ff3bd92fb9134cdbcaa95fce330ab3/snowflake-jdbc-3.13.29.jar, project-references: [ cloveretl.jdbc:snowflake ]

Steps to reproduce

None

Activity

Fixed

Details

Time tracking

6h logged

Priority

Fix versions

QA Testing

UNDECIDED

Created November 5, 2024 at 8:33 AM
Updated last month
Resolved January 9, 2025 at 12:58 PM