PYSEC-2021-333

    Dashboard / Vulnerabilities / PYSEC-2021-333

    PYSEC-2021-333

    Published: 20 Sept 2021Last Modified: 8 Nov 2023

    Summary:

    Details: sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

    Affected packages

    Package

    Name: sqlparse

    Purl: pkg:pypi/sqlparse

    Affected ranges

    Type: GIT

    Events:

    Introduced- 1499cffcd7c4d635b4297b44d48fb4fe94cf988e

    Affected versions

    0.4.0
    0.4.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2021-333 | CVE-DB