Client-side encryption key in DEBUG logs
Low3.3CVE-2025-46329 · Published Apr 28, 2025
# Issue Snowflake discovered and remediated a vulnerability in the Snowflake Connector for C/C++ (“Connector”). When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. This vulnerability affects Connector versions 0.5.0 through 2.1.0. Snowflake fixed the issue in version 2.2.0. # Vulnerability Details When the logging level was set to DEBUG, the Connector would locally log the client-side encryption master key of the target stage during the execution of GET/PUT commands. The key was logged under the name queryStageMasterKey. The key by itself does not grant access to any sensitive data. # Solution Snowflake released version 2.2.0 of the Snowflake Connector for C/C++, which fixes this issue. We recommend users upgrade to version 2.2.0. # Additional Information If you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program h...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| libsnowflakeclient Product | >= 0.5.0, < 2.2.0 | 2.2.0 |
Details and references
# Issue Snowflake discovered and remediated a vulnerability in the Snowflake Connector for C/C++ (“Connector”). When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. This vulnerability affects Connector versions 0.5.0 through 2.1.0. Snowflake fixed the issue in version 2.2.0. # Vulnerability Details When the logging level was set to DEBUG, the Connector would locally log the client-side encryption master key of the target stage during the execution of GET/PUT commands. The key was logged under the name queryStageMasterKey. The key by itself does not grant access to any sensitive data. # Solution Snowflake released version 2.2.0 of the Snowflake Connector for C/C++, which fixes this issue. We recommend users upgrade to version 2.2.0. # Additional Information If you discover a security vulnerability in one of our products or websites, please report the issue to Snowflake through our Vulnerability Disclosure Program hosted at HackerOne. For more information, please see our [Vulnerability Disclosure Policy](https://hackerone.com/snowflake?type=team).
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
More Snowflake advisories
All Snowflake| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 282025 | Race condition when checking access to Easy Logging configuration file | Low3.3 | 2.0.4 |
| Apr 282025 | Race condition when checking access to Easy Logging configuration file | Low3.3 | 1.13.3 |
| Apr 282025 | Retrying of malformed requests | Low3.3 | 2.2.0 |
| Apr 282025 | Race condition when checking access to Easy Logging configuration file | Low3.3 | 4.4.1 |
| Mar 132025 | Client-side encryption key in DEBUG logs | Low3.3 | 3.23.1 |
| Jan 292025 | Insecure cache files permissions | Medium4.4 | 3.13.1 |