Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-43441

Опубликовано: 16 мар. 2023
Источник: debian
EPSS Низкий

Описание

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-sqlite3fixed5.1.5+ds1-1package
node-sqlite3not-affectedbusterpackage

Примечания

  • https://github.com/TryGhost/node-sqlite3/security/advisories/GHSA-jqv5-7xpx-qj74

  • Fixed by: https://github.com/TryGhost/node-sqlite3/commit/edb1934dd222ae55632e120d8f64552d5191c781 (v5.1.5)

EPSS

Процентиль: 91%
0.06448
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 3 года назад

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 8.1
nvd
почти 3 года назад

A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 8.1
github
почти 3 года назад

sqlite vulnerable to code execution due to Object coercion

EPSS

Процентиль: 91%
0.06448
Низкий