Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade sqlite dependency to 3.42.0.0 to mitigate CVE-2023-32697 #15114

Closed
lukaseder opened this issue May 24, 2023 · 2 comments
Closed

Upgrade sqlite dependency to 3.42.0.0 to mitigate CVE-2023-32697 #15114

lukaseder opened this issue May 24, 2023 · 2 comments

Comments

@lukaseder
Copy link
Member

Another one of these "high priority" CVE-2023-32697's has been published:

I mean, when an attacker gets control over the JDBC url, then a specific CVE isn't really the biggest problem I suspect? But alas, we make dependabot happy...

@lukaseder lukaseder added T: Defect C: Build P: High E: All Editions dependencies Pull requests that update a dependency file labels May 24, 2023
@lukaseder lukaseder added this to the Version 3.19.0 milestone May 24, 2023
@lukaseder lukaseder added this to To do in 3.19 Other improvements via automation May 24, 2023
3.19 Other improvements automation moved this from To do to Done May 24, 2023
@lukaseder
Copy link
Member Author

There don't seem to be any interesting improvements to the SQL dialect, so no new dialect is needed: https://www.sqlite.org/changes.html

@lukaseder
Copy link
Member Author

I was very wrong. There's a big, incompatible change! #15125

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
Development

No branches or pull requests

1 participant