Описание
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
sqlparse | fixed | 0.5.0-1 | package | |
sqlparse | fixed | 0.4.2-1+deb12u1 | bookworm | package |
sqlparse | postponed | buster | package |
Примечания
Fixed by: https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03 (0.5.0)
https://github.com/advisories/GHSA-2m57-hf25-phgg
EPSS
Процентиль: 94%
0.12788
Средний
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
CVSS3: 7.5
redhat
около 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
CVSS3: 7.5
nvd
около 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
EPSS
Процентиль: 94%
0.12788
Средний