Logo
vulnerabilityCVE-2023-30608
Name
CVE-2023-30608
Source
NVD ( link)Debian ( link)
Description
sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-sqlparse
Patched

Vulnerability Ratings#


5.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
scarthgap
0.4.4
Not Affected

Resolved with patches#


python3-sqlparse (yocto:kirkstone)

#
Title
Author
Resolve
1
Remove unnecessary parts in regex for bad escaping.
Andi Albrecht <albrecht.andi@gmail.com>
CVE-2023-30608