The Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

Security leaders must ensure their Snowflake accounts are updated with the latest version of the 'snowflake-storage' package to prevent unauthorized access to sensitive data.

Bottom line: Security leaders must ensure their Snowflake accounts are updated with the latest version of the 'snowflake-storage' package to prevent unauthorized access to sensitive data.

What's happening: Snowflake's GitHub repository was vulnerable to a critical CVE-2022-41941 flaw in the 'snowflake-storage' package, exposed to unauthorized access, for over 10 months, from March 2023, due to a missing dependency on the package.

What to do: Security leaders should immediately update their Snowflake accounts to the latest version of the 'snowflake-storage' package, which is version 2.0.0, to prevent unauthorized access to sensitive data.

Source: Infosecurity Magazine