Sqlparse Project Sqlparse 0.1.17 for Python

CPE Details

Sqlparse Project Sqlparse 0.1.17 for Python
0.1.17
2023-04-25
15h53 +00:00
2023-05-01
11h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sqlparse_project:sqlparse:0.1.17:*:*:*:*:python:*:*

Informations

Vendor

sqlparse_project

Product

sqlparse

Version

0.1.17

Target Software

python

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-30608 2023-04-18 21h32 +00:00 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
7.5
High