Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-21227

Опубликовано: 01 мая 2022
Источник: debian
EPSS Низкий

Описание

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-sqlite3fixed5.0.6+ds1-1package
node-sqlite3fixed5.0.0+ds1-1+deb11u1bullseyepackage
node-sqlite3not-affectedbusterpackage
node-sqlite3end-of-lifestretchpackage

Примечания

  • https://github.com/advisories/GHSA-9qrh-qjmc-5w2p

  • Fixed by: https://github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4a (v5.0.3)

  • https://security.snyk.io/vuln/SNYK-JS-SQLITE3-2388645

  • Introduced by: https://github.com/TryGhost/node-sqlite3/commit/dd3ef522088bb5cafede25b9fe661f892b6f10ba (v5.0.0)

EPSS

Процентиль: 80%
0.02068
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS3: 7.5
redhat
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS3: 7.5
nvd
больше 4 лет назад

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS3: 7.5
github
больше 4 лет назад

Denial-of-Service when binding invalid parameters in sqlite3

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость компонента V8 системы управления базами данных SQLite позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 80%
0.02068
Низкий