CVE-2022-46908 Information
Dec 13, 2022
cve
Description
SQLite through 3.40.0 when relying on –safe for execution of an untrusted CLI script does not properly implement the azProhibitedFunctions protection mechanism and instead allows UDF functions such as WRITEFILE.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://sqlite.org/src/info/cefc032473ac5ad2 https://sqlite.org/forum/forumpost/07beac8056151b2f https://news.ycombinator.com/item?id=33948588
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: