OESA-2023-1279

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1279
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1279.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1279
Upstream
Published
2023-05-12T11:05:15Z
Modified
2025-08-12T05:19:56.080135Z
Summary
python-sqlparse security update
Details

sqlparse is a non-validating SQL parser module. It provides support for parsing, splitting and formatting SQL statements.

Security Fix(es):

sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit e75e358. The vulnerability may lead to Denial of Service (DoS). This issues has been fixed in sqlparse 0.4.4 by commit c457abd5f. Users are advised to upgrade. There are no known workarounds for this issue. (CVE-2023-30608)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-sqlparse

Package

Name
python-sqlparse
Purl
pkg:rpm/openEuler/python-sqlparse&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.1-2.oe1

Ecosystem specific

{
    "noarch": [
        "python-sqlparse-help-0.3.1-2.oe1.noarch.rpm",
        "python3-sqlparse-0.3.1-2.oe1.noarch.rpm"
    ],
    "src": [
        "python-sqlparse-0.3.1-2.oe1.src.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / python-sqlparse

Package

Name
python-sqlparse
Purl
pkg:rpm/openEuler/python-sqlparse&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.1-2.oe1

Ecosystem specific

{
    "noarch": [
        "python-sqlparse-help-0.3.1-2.oe1.noarch.rpm",
        "python3-sqlparse-0.3.1-2.oe1.noarch.rpm"
    ],
    "src": [
        "python-sqlparse-0.3.1-2.oe1.src.rpm"
    ]
}

openEuler:22.03-LTS / python-sqlparse

Package

Name
python-sqlparse
Purl
pkg:rpm/openEuler/python-sqlparse&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.2-2.oe2203sp1

Ecosystem specific

{
    "noarch": [
        "python3-sqlparse-0.4.1-3.oe2203.noarch.rpm",
        "python-sqlparse-help-0.4.1-3.oe2203.noarch.rpm",
        "python-sqlparse-help-0.4.2-2.oe2203sp1.noarch.rpm",
        "python3-sqlparse-0.4.2-2.oe2203sp1.noarch.rpm"
    ],
    "src": [
        "python-sqlparse-0.4.1-3.oe2203.src.rpm",
        "python-sqlparse-0.4.2-2.oe2203sp1.src.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / python-sqlparse

Package

Name
python-sqlparse
Purl
pkg:rpm/openEuler/python-sqlparse&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.2-2.oe2203sp1

Ecosystem specific

{
    "noarch": [
        "python-sqlparse-help-0.4.2-2.oe2203sp1.noarch.rpm",
        "python3-sqlparse-0.4.2-2.oe2203sp1.noarch.rpm"
    ],
    "src": [
        "python-sqlparse-0.4.2-2.oe2203sp1.src.rpm"
    ]
}