CVE-2022-46908

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*

History

24 Nov 2023, 14:15

Type Values Removed Values Added
References
  • () https://security.gentoo.org/glsa/202311-03 -

07 Mar 2023, 18:21

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20230203-0005/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20230203-0005/ - Third Party Advisory

03 Feb 2023, 10:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230203-0005/ -

20 Dec 2022, 20:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.3

12 Dec 2022, 18:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-Other
CPE cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
References (MISC) https://news.ycombinator.com/item?id=33948588 - (MISC) https://news.ycombinator.com/item?id=33948588 - Exploit, Issue Tracking, Third Party Advisory
References (MISC) https://sqlite.org/forum/forumpost/07beac8056151b2f - (MISC) https://sqlite.org/forum/forumpost/07beac8056151b2f - Exploit, Issue Tracking, Vendor Advisory
References (MISC) https://sqlite.org/src/info/cefc032473ac5ad2 - (MISC) https://sqlite.org/src/info/cefc032473ac5ad2 - Patch, Vendor Advisory
First Time Sqlite
Sqlite sqlite

12 Dec 2022, 11:26

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-12 06:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-46908

Mitre link : CVE-2022-46908

CVE.ORG link : CVE-2022-46908


JSON object : View

Products Affected

sqlite

  • sqlite