digital-asset / digital-asset/daml
Critical security vulnerability for daml 2.8.4
- Dominant language
- Haskell
- Stars
- 917
- Forks
- 263
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 45
Description
Hello,
We use Aqua for our sdlc and it reported a critical vulnerability found in `/home/daml/.daml/sdk/2.8.4/daml-sdk/daml-sdk.jar` impacting `sqlite-jdbc 3.36.0.1`.
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

Thanks,
Tony
Contributor guide
Research direction
Start by tracing the dependency in /home/daml/.daml/sdk/2.8.4/daml-sdk/daml-sdk.jar and locating sqlite-jdbc 3.36.0.1 in the repository or SDK build inputs. Confirm the SDK no longer ships the vulnerable version, rebuild the relevant artifact, and verify its dependency metadata reports the fixed release.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, sqlite
- Domain
- databases, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100