HIGH8.8
GHSA-6phf-6h5g-97j2
Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
Quick fix
GHSA-6phf-6h5g-97j2 — org.xerial:sqlite-jdbc: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.41.2.2</version> for org.xerial:sqlite-jdbcDetails
## Summary
Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL.
## Impacted versions :
3.6.14.1-3.41.2.1 ## References
https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.xerial:sqlite-jdbc
Introduced in:
3.6.14.1Fixed in: 3.41.2.2Fix
# pom.xml: bump <version>3.41.2.2</version> for org.xerial:sqlite-jdbc