Skip to main content

Protection Mechanism Failure

CVE-2022-46908

Severity High
Score 7.3/10

Summary

SQLite prior to 3.40.1. When relying on "--safe" for the execution of an untrusted CLI script, does not properly implement the "azProhibitedFunctions" protection mechanism, and instead allows UDF functions such as "WRITEFILE".

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • LOW

CWE-693 - Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Advisory Timeline

  • Published