VDB
BDU%3A2025-01019
BDU%3A2025-01019
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции sqlparse.parse() модуля парсера SQL для Python Sqlparse, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc., ООО «РусБИТех-Астра» | OpenSUSE Leap, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, Red Hat Satellite, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Public Cloud, SUSE Enterprise Storage, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, Red Hat Update Infrastructure for Cloud Providers, Red Hat OpenStack Platform, Red Hat Ansible Automation Platform, Sqlparse, ПК "ALD Pro" |
Timeline
- Feb 3, 2025 CVE Published
- Nov 26, 2025 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-python3-sqlparse-cve-2024-4340/?sphrase_id=644380 url
- https://github.com/advisories/GHSA-2m57-hf25-phgg url
- https://github.com/andialbrecht/sqlparse/commit/b4a39d9850969b4e1d6940d32094ee0b42a2cf03 url
- https://research.jfrog.com/vulnerabilities/sqlparse-stack-exhaustion-dos-jfsa-2024-001031292/ url
- https://security-tracker.debian.org/tracker/CVE-2024-4340 url
- https://access.redhat.com/security/cve/cve-2024-4340 url
- https://www.suse.com/security/cve/CVE-2024-4340.html url
- https://lk.astra.ru/ url
- https://wiki.astralinux.ru/x/ziLoD url