{"id":"CVE-2023-32697","aliases":["GHSA-6phf-6h5g-97j2"],"url":"https://o3.security/vulnerability/CVE-2023-32697","summary":"Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled","details":"SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.\n","published":"2023-05-23T22:45:10.493Z","modified":"2026-08-12T03:51:38.012106308Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xerial:sqlite-jdbc","fixedVersion":"3.41.2.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32697.json"},{"type":"ADVISORY","url":"https://github.com/xerial/sqlite-jdbc/security/advisories/GHSA-6phf-6h5g-97j2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32697"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.012106308Z"}}