CVE-2024-4340
CVSS V2 None
CVSS V3 None
Description
Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
Overview
- CVE ID
- CVE-2024-4340
- Assigner
- JFROG
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-30T14:23:03.435Z
- Last Modified Date
- 2024-06-04T17:54:10.848Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://research.jfrog.com/vulnerabilities/sqlparse-stack-exhaustion-dos-jfsa-2024-001031292/ | third-party-advisory |
https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03 | patch |
https://github.com/advisories/GHSA-2m57-hf25-phgg |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-4340 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4340 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-23 22:41:12 | Added to TrackCVE |