PT-2023-3225 · Pypi+6 · Sqlparse+6
Erik-Krogh
·
Published
2023-04-18
·
Updated
2024-12-21
·
CVE-2023-30608
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
sqlparse versions prior to 0.4.4
Description
The SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue may lead to Denial of Service (DoS). The vulnerability was introduced by commit
e75e358 and has been fixed in sqlparse 0.4.4 by commit c457abd5f.Recommendations
For versions prior to 0.4.4, upgrade to sqlparse 0.4.4 to resolve the issue. As a temporary workaround, consider restricting the use of the SQL parser until a patch is available. There are no known workarounds for this issue.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Red Os
Rocky Linux
Suse
Ubuntu
Sqlparse