Описание
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit e75e358
. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit c457abd5f
. Users are advised to upgrade. There are no known workarounds for this issue.
A flaw was found in sqlparse. The SQL parser contains a regular expression vulnerable to a Regular Expression Denial of Service (ReDoS). The vulnerability may lead to a denial of service (DoS).
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | python-sqlparse | Affected | ||
Red Hat OpenShift Container Platform 4 | python-sqlparse | Will not fix | ||
Red Hat OpenStack Platform 13 (Queens) | python-sqlparse | Out of support scope | ||
Red Hat OpenStack Platform 16.1 | python-sqlparse | Will not fix | ||
Red Hat OpenStack Platform 16.2 | python-sqlparse | Will not fix | ||
Red Hat OpenStack Platform 17.0 | python-sqlparse | Out of support scope | ||
Red Hat Satellite 6.14 for RHEL 8 | python-sqlparse | Fixed | RHSA-2023:6818 | 08.11.2023 |
Red Hat Satellite 6.14 for RHEL 8 | python-sqlparse | Fixed | RHSA-2023:6818 | 08.11.2023 |
RHUI 4 for RHEL 8 | python-sqlparse | Fixed | RHSA-2023:4591 | 09.08.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
sqlparse is a non-validating SQL parser module for Python. In affected ...
EPSS
7.5 High
CVSS3