Improper authorization control for web services In node-sqlite3
Description
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 5.0.0+ds1-1+deb11u2 | ||
npm | 5.1.5 | ||
debian 12 | 5.1.5+ds1-1 | ||
debian 13 | 5.1.5+ds1-1 | ||
debian 14 | 5.1.5+ds1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.