VDB
Sign up
HIGH8.8

GHSA-6phf-6h5g-97j2

Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled

Quick fix

GHSA-6phf-6h5g-97j2 — org.xerial:sqlite-jdbc: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.41.2.2</version> for org.xerial:sqlite-jdbc

Details

## Summary

Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL.

## Impacted versions :

3.6.14.1-3.41.2.1 ## References

https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.xerial:sqlite-jdbc
Introduced in: 3.6.14.1Fixed in: 3.41.2.2
Fix# pom.xml: bump <version>3.41.2.2</version> for org.xerial:sqlite-jdbc

References