Headline
CVE-2023-32697: Release Release 3.41.2.2 · xerial/sqlite-jdbc
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.
Changelog****🚀 Features
jdbc
- add support for LocalDate, LocalTime, LocalDateTime in ResultSet#getObject (1d2ff63)
- implement PreparedStatement getParameterType and getParameterTypeName (bdb3d8a)
native-image
- resource optimization and configuration to export native lib (6f42683)
🐛 Fixes
- use random UUID for external resources (edb4b8a)
🛠 Build
deps
- bump native-maven-plugin from 0.9.21 to 0.9.22 (48e8ebe)
- bump graal-sdk from 22.3.0 to 22.3.2 (128d9b2)
- bump surefire.version from 3.0.0 to 3.1.0 (658e907)
- bump maven-gpg-plugin from 3.0.1 to 3.1.0 (f149f9f)
- bump jreleaser-maven-plugin from 1.5.1 to 1.6.0 (d028636)
- bump native-maven-plugin from 0.9.20 to 0.9.21 (08b5e35)
- bump maven-enforcer-plugin from 3.2.1 to 3.3.0 (3b3af82)
- bump maven-compiler-plugin from 3.10.1 to 3.11.0 (52b7701)
- bump versions-maven-plugin from 2.13.0 to 2.15.0 (a0e0191)
- bump maven-help-plugin from 3.3.0 to 3.4.0 (739a27c)
deps-dev
- bump junit-jupiter from 5.9.2 to 5.9.3 (e64e348)
- bump mockito-core from 5.3.0 to 5.3.1 (6e94e6b)
- bump logback-classic from 1.4.6 to 1.4.7 (5a4f485)
- bump mockito-core from 5.2.0 to 5.3.0 (d0adb0f)
- bump junit-pioneer from 2.0.0 to 2.0.1 (2b00983)
- bump junit-jupiter from 5.9.1 to 5.9.2 (c917e81)
- bump logback-classic from 1.4.5 to 1.4.6 (eab4939)
unscoped
- replace jdk 19 with 20 (0c5a645)
- replace asciidoc variables during release (0053e60)
- run spotless:check during maven verify phase (043efd7)
📝 Documentation
- use markdown for SECURITY.md because Github doesn’t support Asciidoc (00e9c3f)
- convert markdown to asciidoc (fb0f263)
Contributors
We’d like to thank the following people for their contributions:
Andrew Pikler, Andy Cheung, Gauthier, Gauthier Roebroeck, Javier Goday, Kristof, Taro L. Saito
Related news
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138
## Summary Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. ## Impacted versions : 3.6.14.1-3.41.2.1 ## References https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2