Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq57-m32w-cmv5

Опубликовано: 30 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension injection via the custom extension feature.

DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension injection via the custom extension feature.

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

nvd
около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

9.8 Critical

CVSS3

Дефекты

CWE-89