CVE-2023-30608
Summary
| CVE | CVE-2023-30608 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-18 22:15:00 UTC |
| Updated | 2023-06-14 18:14:00 UTC |
| Description | sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3425-1] sqlparse security update |
MISC |
lists.debian.org |
|
| Regular expression Denial of Service - ReDoS | OWASP Foundation |
MISC |
owasp.org |
|
| Remove unnecessary parts in regex for bad escaping. · andialbrecht/sqlparse@c457abd · GitHub |
MISC |
github.com |
|
| Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) · Advisory · andialbrecht/sqlparse · GitHub |
MISC |
github.com |
|
| Recognize escaped backslashes within strings · andialbrecht/sqlparse@e75e358 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181788 Debian Security Update for sqlparse (DLA 3425-1)
- 199333 Ubuntu Security Notification for Structured Query Language (SQL) parse Vulnerability (USN-6064-1)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 754131 SUSE Enterprise Linux Security Update for python-sqlparse (SUSE-SU-2023:2619-1)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)