In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade sqlite
to version 3.34.0 or higher.
This was deemed not a vulnerability.
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in fts5UnicodeTokenize()
in ext/fts5/fts5_tokenize.c
, where a unicode61
tokenizer configured to treat unicode "control-characters" is treating embedded null characters as tokens.
Note: CVE-2021-20223 has been retracted because it was found to be invalid. Further investigation showed that it was not a security issue.