PT-2024-19529 · Unknown+1 · Duckdb Extension-Template+1

Published

2024-01-30

·

Updated

2024-07-19

·

CVE-2024-22682

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DuckDB versions prior to 0.9.3 DuckDB extension-template versions prior to 0.9.3
Description The issue allows for malicious extension injection through the custom extension feature.
Recommendations For DuckDB versions prior to 0.9.3, update to version 0.9.3 or later to resolve the issue. For DuckDB extension-template versions prior to 0.9.3, update to version 0.9.3 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2024-22682
PYSEC-2024-25

Affected Products

Duckdb
Duckdb Extension-Template