Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-30608

Опубликовано: 18 апр. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit e75e358. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit c457abd5f. Users are advised to upgrade. There are no known workarounds for this issue.

РелизСтатусПримечание
bionic

released

0.2.4-0.1ubuntu0.1
devel

released

0.4.2-1ubuntu1
esm-infra/bionic

not-affected

0.2.4-0.1ubuntu0.1
esm-infra/focal

not-affected

0.2.4-3ubuntu0.1
esm-infra/xenial

not-affected

code not present
focal

released

0.2.4-3ubuntu0.1
jammy

released

0.4.2-1ubuntu0.22.04.1
kinetic

released

0.4.2-1ubuntu0.22.10.1
lunar

released

0.4.2-1ubuntu0.23.04.1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 57%
0.0036
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 лет назад

sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.5
nvd
около 2 лет назад

sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.5
debian
около 2 лет назад

sqlparse is a non-validating SQL parser module for Python. In affected ...

suse-cvrf
почти 2 года назад

Security update for python-sqlparse

suse-cvrf
около 2 лет назад

Security update for python-sqlparse

EPSS

Процентиль: 57%
0.0036
Низкий

5.5 Medium

CVSS3