CVE-2022-21227Uncaught Exception in Sqlite3

Severity
7.5HIGHNVD
EPSS
0.3%
top 43.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1

Description

The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5ghost/sqlite3unspecified5.0.3
NVDghost/sqlite3< 5.0.3
npmghost/sqlite35.0.05.0.3

Patches

🔴Vulnerability Details

4
CVEList
Denial of Service (DoS)2022-05-01
OSV
CVE-2022-21227: The package sqlite3 before 52022-05-01
GHSA
Denial-of-Service when binding invalid parameters in sqlite32022-04-28
OSV
Denial-of-Service when binding invalid parameters in sqlite32022-04-28

📋Vendor Advisories

2
Red Hat
sqlite3: Denial of Service (DoS) in sqlite32022-05-01
Debian
CVE-2022-21227: node-sqlite3 - The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which...2022
CVE-2022-21227 — Uncaught Exception in Ghost Sqlite3 | cvebase