PT-2023-3225 · Pypi+6 · Sqlparse+6
Erik-Krogh
·
Publicado
2023-04-18
·
Atualizado
2024-12-21
·
CVE-2023-30608
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
sqlparse versions prior to 0.4.4
Description
The SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue may lead to Denial of Service (DoS). The vulnerability was introduced by commit
e75e358 and has been fixed in sqlparse 0.4.4 by commit c457abd5f.Recommendations
For versions prior to 0.4.4, upgrade to sqlparse 0.4.4 to resolve the issue. As a temporary workaround, consider restricting the use of the SQL parser until a patch is available. There are no known workarounds for this issue.
Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astra Linux
Linuxmint
Red Os
Rocky Linux
Suse
Ubuntu
Sqlparse