Sqlparse Project Sqlparse 0.2.2 for Python

CPE Details

Sqlparse Project Sqlparse 0.2.2 for Python
0.2.2
2023-04-25
15h53 +00:00
2023-05-01
11h23 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:sqlparse_project:sqlparse:0.2.2:*:*:*:*:python:*:*

Informations

Vendor

sqlparse_project

Product

sqlparse

Version

0.2.2

Target Software

python

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-30608 2023-04-18 21h32 +00:00 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit `c457abd5f`. Users are advised to upgrade. There are no known workarounds for this issue.
7.5
Haute