Lucene search

K
osvGoogleOSV:BIT-SQLITE-2022-46908
HistoryMar 06, 2024 - 11:05 a.m.

BIT-sqlite-2022-46908

2024-03-0611:05:50
Google
osv.dev
15
sqlite
udf functions
writefile
cli script
protection mechanism

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

0.001 Low

EPSS

Percentile

23.8%

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

CPENameOperatorVersion
sqlitelt3.40.1
sqlitege3.37.0

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

0.001 Low

EPSS

Percentile

23.8%