CVE-2019-19924: Apache Bookkeeper

Medium severity, CVSS 5.3. EPSS: 7.9% chance of exploitation in the next 30 days.

SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.

Affected products

  • Apache Bookkeeper: version 4.12.1 only
  • Netapp Cloud Backup: affected versions not specified
  • Oracle MySQL Workbench: up to and including 8.0.19
  • Siemens Sinec Infrastructure Network Services: before 1.0.1.1 (fixed in 1.0.1.1)
  • Sqlite Sqlite: version 3.30.1 only

Published 2019-12-24. Last modified 2026-06-17.