CVE-2023-32697
Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
Description
Summary
Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL.
Impacted versions :
3.6.14.1-3.41.2.1
References
https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2
Base CVSS
8.8
EPSS Score
5.28%
Introduced Version
3.6.14.1
Fix Available
3.41.2.2
Available Patches
Package
CVEs Fixed
Lines of Code Changed