{"id":"CVE-2023-32697","summary":"Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled","details":"SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.\n","aliases":["GHSA-6phf-6h5g-97j2"],"modified":"2026-08-12T03:51:38.012106308Z","published":"2023-05-23T22:45:10.493Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32697.json"},"references":[{"type":"WEB","url":"https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32697.json"},{"type":"ADVISORY","url":"https://github.com/xerial/sqlite-jdbc/security/advisories/GHSA-6phf-6h5g-97j2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32697"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xerial/sqlite-jdbc","events":[{"introduced":"0"},{"fixed":"080c808eac7612f90852e09088f75806afafa15b"}],"database_specific":{"extracted_events":[{"introduced":"3.6.14.1"},{"fixed":"3.41.2.2"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sqlite_jdbc_project:sqlite_jdbc:*:*:*:*:*:*:*:*"}}],"versions":["3.41.2.1","3.41.0.1","3.41.0.0","3.40.1.0","3.40.0.0","3.39.4.1","3.39.4.0","3.39.3.0","3.39.2.1","3.39.2.0","3.36.0.3","3.36.0.2","3.36.0.1","3.36.0","3.35.0.1","3.35.0","3.34.0","3.32.3.3","3.32.3.2","3.32.3.1","3.32.3","3.31.1","3.30.1","3.28.0","3.27.2.1","3.27.2","3.25.2","3.23.1","3.21.0.1","3.21.0","3.20.1","3.20.0","3.19.3","3.18.0","3.16.1","3.15.1","3.15.0","3.14.2.1","3.14.2","3.8.11.2","3.8.11.1","3.8.11","3.8.10.2","3.8.10.1","3.8.9.1","3.8.9","3.8.6","3.8.5-pre1","sqlite-jdbc-3.7.2","3.7.15-SNAPSHOT-2-win-linux","3.7.15-SNAPSHOT-1-win-linux","sqlite-jdbc-3.7.15","sqlite-jdbc-3.6.20.1","sqlite-jdbc-3.6.20","sqlite-jdbc-3.6.19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32697.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}