The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
References
Link | Resource |
---|---|
https://github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4a | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2805470 | Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-SQLITE3-2388645 | Third Party Advisory |
https://github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4a | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2805470 | Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-SQLITE3-2388645 | Third Party Advisory |
Configurations
History
21 Nov 2024, 06:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4a - Patch, Third Party Advisory | |
References | () https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2805470 - Third Party Advisory | |
References | () https://snyk.io/vuln/SNYK-JS-SQLITE3-2388645 - Third Party Advisory |
Information
Published : 2022-05-01 16:15
Updated : 2024-11-21 06:44
NVD link : CVE-2022-21227
Mitre link : CVE-2022-21227
CVE.ORG link : CVE-2022-21227
JSON object : View
Products Affected
ghost
- sqlite3
CWE