CVE-2024-22682 – duckdb
Package
Manager: pip
Name: duckdb
Vulnerable Version: =0.0.0 || =0.0.2 || =0.0.3 || =0.1.0 || =0.1.1 || =0.1.2 || =0.1.3 || =0.1.5 || =0.1.6 || =0.1.7 || =0.1.8 || =0.1.9 || =0.2.0 || =0.2.1 || =0.2.2 || =0.2.3 || =0.2.4 || =0.2.5 || =0.2.6 || =0.2.7 || =0.2.8 || =0.2.9 || =0.3.0 || =0.3.1 || =0.3.2 || =0.3.3 || =0.3.4 || =0.4.0 || =0.5.0 || =0.5.1 || =0.6.0 || =0.6.1 || =0.7.0 || =0.7.1 || =0.8.0 || =0.8.1 || =0.9.0 || =0.9.1 || =0.9.2 || >=0 <0.9.3.dev6
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension injection via the custom extension feature.
Metadata
Created: 2024-01-30T01:16:00Z
Modified: 2024-02-06T01:11:38.987577Z
Source: https://osv-vulnerabilities
CWE IDs: N/A
Alternative ID: N/A
Finding: F422
Auto approve: 1