CVE-2025-46614
LOWCVSS 3.3/10EPSS 0.13%
Last modified
CVE-2025-46614 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-46614?
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
How severe is CVE-2025-46614?
CVE-2025-46614 has a CVSS score of 3.3/10 (LOW severity). The EPSS model estimates a 0.13% probability of exploitation in the next 30 days.
How do I fix CVE-2025-46614?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46608Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) a…7.2
- CVE-2025-4661A path transversal vulnerability in Brocade Fabric OS 9.1.0…2.3
- CVE-2025-46610ARTEC EMA Mail 6.92 allows CSRF.8.8
- CVE-2025-46611Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 a…6.1
- CVE-2025-46612The Panel Designer dashboard in Airleader Master and Easy be…7.2
- CVE-2025-46613OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption b…7.5
- CVE-2025-46616Quantum StorNext Web GUI API before 7.2.4 allows potential A…9.9
- CVE-2025-46617Quantum StorNext Web GUI API before 7.2.4 grants access to i…7.2
- CVE-2025-46618In JetBrains TeamCity before 2025.03.1 stored XSS was possib…6.1
- CVE-2025-46619A security issue has been discovered in Couchbase Server bef…7.6
- CVE-2025-4662Brocade SANnav before SANnav 2.4.0a logs plaintext passphras…4.4
- CVE-2025-46625Lack of input validation/sanitization in the 'setLanCfg' API…8.8
Are you affected by CVE-2025-46614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
