Описание
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| sqlparse | fixed | 0.5.0-1 | package | |
| sqlparse | fixed | 0.4.2-1+deb12u1 | bookworm | package |
| sqlparse | postponed | buster | package |
Примечания
Fixed by: https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03 (0.5.0)
https://github.com/advisories/GHSA-2m57-hf25-phgg
EPSS
Процентиль: 94%
0.15162
Средний
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
CVSS3: 7.5
redhat
больше 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
CVSS3: 7.5
nvd
больше 1 года назад
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
EPSS
Процентиль: 94%
0.15162
Средний