Описание
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit e75e358
. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit c457abd5f
. Users are advised to upgrade. There are no known workarounds for this issue.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 0.2.4-0.1ubuntu0.1 |
devel | released | 0.4.2-1ubuntu1 |
esm-infra/bionic | not-affected | 0.2.4-0.1ubuntu0.1 |
esm-infra/focal | not-affected | 0.2.4-3ubuntu0.1 |
esm-infra/xenial | not-affected | code not present |
focal | released | 0.2.4-3ubuntu0.1 |
jammy | released | 0.4.2-1ubuntu0.22.04.1 |
kinetic | released | 0.4.2-1ubuntu0.22.10.1 |
lunar | released | 0.4.2-1ubuntu0.23.04.1 |
trusty | ignored | end of standard support |
Показывать по
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
sqlparse is a non-validating SQL parser module for Python. In affected ...
EPSS
5.5 Medium
CVSS3