PT-2023-4867 · Unknown · Sqlite-Jdbc

4390C336

·

Publicado

2023-05-23

·

Atualizado

2023-11-10

·

CVE-2023-32697

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sqlite-jdbc versions 3.6.14.1 through 3.41.2.1
Description The issue is related to a remote code execution vulnerability via JDBC URL, which can be exploited by a remote attacker to execute arbitrary code. This is due to incorrect code generation management in the SQLite JDBC library.
Recommendations For versions 3.6.14.1 through 3.41.2.1, update to version 3.41.2.2 to resolve the issue. As a temporary workaround, consider restricting access to the JDBC URL to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05354
CVE-2023-32697
GHSA-6PHF-6H5G-97J2
OESA-2023-1792

Produtos afetados

Sqlite-Jdbc