SQLite through 3.40.0, when relying on –safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sqlite | Sqlite | 3.37.0 (including) | 3.40.1 (excluding) |
| Sqlite3 | Ubuntu | jammy | * |
| Sqlite3 | Ubuntu | kinetic | * |
| Sqlite3 | Ubuntu | upstream | * |