CVE-2022-21227
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
- Ghost sqlite3
- < 5.0.3
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2022-05-01
CVE-2022-21227 at NVD
No indexed exploits for CVE-2022-21227 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-21227 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.