PT-2023-3225 · Pypi+6 · Sqlparse+6

Erik-Krogh

·

Publicado

2023-04-18

·

Atualizado

2024-12-21

·

CVE-2023-30608

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions sqlparse versions prior to 0.4.4
Description The SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue may lead to Denial of Service (DoS). The vulnerability was introduced by commit e75e358 and has been fixed in sqlparse 0.4.4 by commit c457abd5f.
Recommendations For versions prior to 0.4.4, upgrade to sqlparse 0.4.4 to resolve the issue. As a temporary workaround, consider restricting the use of the SQL parser until a patch is available. There are no known workarounds for this issue.

Exploit

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03345
CVE-2023-30608
DLA-3425-1
DLA-4000-1
GHSA-RRM6-WVJ7-CWH2
MGASA-2023-0183
OESA-2023-1279
OPENSUSE-SU-2024:12957-1
PYSEC-2023-87
RHSA-2023:4591
RHSA-2023:6818
RLSA-2023:6818
SUSE-RU-2024:1637-1
SUSE-RU-2024:1637-2
SUSE-RU-2024:1637-3
SUSE-SU-2023:2462-1
SUSE-SU-2023:2619-1
SUSE-SU-2023:2693-1
SUSE-SU-2023:2787-1
SUSE-SU-2023_2619-1
USN-6064-1

Produtos afetados

Astra Linux
Linuxmint
Red Os
Rocky Linux
Suse
Ubuntu
Sqlparse