PT-2023-3225 · Pypi+6 · Sqlparse+6

Erik-Krogh

·

Published

2023-04-18

·

Updated

2024-12-21

·

CVE-2023-30608

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions sqlparse versions prior to 0.4.4
Description The SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue may lead to Denial of Service (DoS). The vulnerability was introduced by commit e75e358 and has been fixed in sqlparse 0.4.4 by commit c457abd5f.
Recommendations For versions prior to 0.4.4, upgrade to sqlparse 0.4.4 to resolve the issue. As a temporary workaround, consider restricting the use of the SQL parser until a patch is available. There are no known workarounds for this issue.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-03345
CVE-2023-30608
DLA-3425-1
DLA-4000-1
GHSA-RRM6-WVJ7-CWH2
MGASA-2023-0183
OESA-2023-1279
OPENSUSE-SU-2024:12957-1
PYSEC-2023-87
RHSA-2023:4591
RHSA-2023:6818
RLSA-2023:6818
SUSE-RU-2024:1637-1
SUSE-RU-2024:1637-2
SUSE-RU-2024:1637-3
SUSE-SU-2023:2462-1
SUSE-SU-2023:2619-1
SUSE-SU-2023:2693-1
SUSE-SU-2023:2787-1
SUSE-SU-2023_2619-1
USN-6064-1

Affected Products

Astra Linux
Linuxmint
Red Os
Rocky Linux
Suse
Ubuntu
Sqlparse