Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
ID: 36746b30-fb90-580b-8a74-0b8b0c24b476
STIX ID: report--36746b30-fb90-580b-8a74-0b8b0c24b476
Feed Name: Infosecurity Magazine (News)
Threat Score
Wiz Research's autonomous Red Agent discovered a critical script-injection vulnerability in Snowflake's snowflake-connector-net GitHub Actions that allowed unauthenticated attackers to execute arbitrary commands by submitting specially crafted GitHub issue titles; the issue was introduced in a June 18 PR, discovered and reported on June 23, patched the same day, and Snowflake rotated the Jira token and reported no evidence of unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
