Vulnerability Description
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqlite | Sqlite | >= 3.37.0, < 3.40.1 |
References
- https://news.ycombinator.com/item?id=33948588ExploitIssue TrackingThird Party Advisory
- https://security.gentoo.org/glsa/202311-03
- https://security.netapp.com/advisory/ntap-20230203-0005/Third Party Advisory
- https://sqlite.org/forum/forumpost/07beac8056151b2fExploitIssue TrackingVendor Advisory
- https://sqlite.org/src/info/cefc032473ac5ad2PatchVendor Advisory
- https://news.ycombinator.com/item?id=33948588ExploitIssue TrackingThird Party Advisory
- https://security.gentoo.org/glsa/202311-03
- https://security.netapp.com/advisory/ntap-20230203-0005/Third Party Advisory
- https://sqlite.org/forum/forumpost/07beac8056151b2fExploitIssue TrackingVendor Advisory
- https://sqlite.org/src/info/cefc032473ac5ad2PatchVendor Advisory
FAQ
What is CVE-2022-46908?
CVE-2022-46908 is a vulnerability with a CVSS score of 7.3 (HIGH). SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions suc...
How severe is CVE-2022-46908?
CVE-2022-46908 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-46908?
Check the references section above for vendor advisories and patch information. Affected products include: Sqlite Sqlite.