digital-asset / digital-asset/daml

Critical security vulnerability for daml 2.8.4

Open
#19,085 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Haskell
Stars
917
Forks
263
Avg merge
1d 22h
Merged PRs (30d)
45

Description

Hello,

We use Aqua for our sdlc and it reported a critical vulnerability found in `/home/daml/.daml/sdk/2.8.4/daml-sdk/daml-sdk.jar` impacting `sqlite-jdbc 3.36.0.1`.

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

![Screenshot 2024-04-23 at 11 57 07 AM](https://github.com/digital-asset/daml/assets/36517441/b268e65a-2e19-40d2-90c1-5148ad323302)

Thanks,
Tony

Contributor guide

Open the contributing guide

Research direction

Start by tracing the dependency in /home/daml/.daml/sdk/2.8.4/daml-sdk/daml-sdk.jar and locating sqlite-jdbc 3.36.0.1 in the repository or SDK build inputs. Confirm the SDK no longer ships the vulnerable version, rebuild the relevant artifact, and verify its dependency metadata reports the fixed release.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, sqlite
Domain
databases, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.