The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JS-SQLITE3-2388645 | Third Party Advisory |
https://github.com/TryGhost/node-sqlite3/commit/593c9d498be2510d286349134537e3bf89401c4a | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2805470 | Third Party Advisory |
Configurations
Information
Published : 2022-05-01 09:15
Updated : 2022-05-11 07:10
NVD link : CVE-2022-21227
Mitre link : CVE-2022-21227
JSON object : View
CWE
Products Affected
ghost
- sqlite3