diff --git a/advisories/github-reviewed/2024/04/GHSA-2m57-hf25-phgg/GHSA-2m57-hf25-phgg.json b/advisories/github-reviewed/2024/04/GHSA-2m57-hf25-phgg/GHSA-2m57-hf25-phgg.json index b2a1335f62f..c46ff3d6396 100644 --- a/advisories/github-reviewed/2024/04/GHSA-2m57-hf25-phgg/GHSA-2m57-hf25-phgg.json +++ b/advisories/github-reviewed/2024/04/GHSA-2m57-hf25-phgg/GHSA-2m57-hf25-phgg.json @@ -1,10 +1,10 @@ { "schema_version": "1.4.0", "id": "GHSA-2m57-hf25-phgg", - "modified": "2024-05-01T09:32:14Z", + "modified": "2024-05-01T11:09:12Z", "published": "2024-04-15T20:21:25Z", "aliases": [ - + "CVE-2024-4340" ], "summary": "sqlparse parsing heavily nested list leads to Denial of Service", "details": "### Summary\nPassing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.\n\n### Details + PoC\nRunning the following code will raise Maximum recursion limit exceeded exception:\n```py\nimport sqlparse\nsqlparse.parse('[' * 10000 + ']' * 10000)\n```\nWe expect a traceback of RecursionError:\n```py\nTraceback (most recent call last):\n File \"trigger_sqlparse_nested_list.py\", line 3, in \n sqlparse.parse('[' * 10000 + ']' * 10000)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/__init__.py\", line 30, in parse\n return tuple(parsestream(sql, encoding))\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/filter_stack.py\", line 36, in run\n stmt = grouping.group(stmt)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py\", line 428, in group\n func(stmt)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py\", line 53, in group_brackets\n _group_matching(tlist, sql.SquareBrackets)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/engine/grouping.py\", line 48, in _group_matching\n tlist.group_tokens(cls, open_idx, close_idx)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 328, in group_tokens\n grp = grp_cls(subtokens)\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 161, in __init__\n super().__init__(None, str(self))\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 165, in __str__\n return ''.join(token.value for token in self.flatten())\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 165, in \n return ''.join(token.value for token in self.flatten())\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 214, in flatten\n yield from token.flatten()\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 214, in flatten\n yield from token.flatten()\n File \"/home/uriya/.local/lib/python3.10/site-packages/sqlparse/sql.py\", line 214, in flatten\n yield from token.flatten()\n [Previous line repeated 983 more times]\nRecursionError: maximum recursion depth exceeded\n```\n\n### Fix suggestion\nThe [flatten()](https://github.com/andialbrecht/sqlparse/blob/master/sqlparse/sql.py#L207) function of TokenList class should limit the recursion to a maximal depth:\n```py\nfrom sqlparse.exceptions import SQLParseError\n\nMAX_DEPTH = 100\n\n def flatten(self, depth=1):\n \"\"\"Generator yielding ungrouped tokens.\n\n This method is recursively called for all child tokens.\n \"\"\"\n if depth >= MAX_DEPTH:\n raise SQLParseError('Maximal depth reached')\n for token in self.tokens:\n if token.is_group:\n yield from token.flatten(depth + 1)\n else:\n yield token\n```\n\n### Impact\nDenial of Service (the impact depends on the use).\nAnyone parsing a user input with sqlparse.parse() is affected.\n", diff --git a/advisories/unreviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json b/advisories/github-reviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json similarity index 50% rename from advisories/unreviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json rename to advisories/github-reviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json index 96e5cee8e28..c3b94ce05d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json +++ b/advisories/github-reviewed/2024/04/GHSA-62qf-jcq8-8gxw/GHSA-62qf-jcq8-8gxw.json @@ -1,12 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-62qf-jcq8-8gxw", - "modified": "2024-04-30T15:30:38Z", + "modified": "2024-05-01T11:08:47Z", "published": "2024-04-30T15:30:38Z", + "withdrawn": "2024-05-01T11:08:47Z", "aliases": [ - "CVE-2024-4340" + ], - "details": "Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.\n\n", + "summary": "Duplicate Advisory: sqlparse parsing heavily nested list leads to Denial of Service", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2m57-hf25-phgg. This link is maintained to preserve external references.\n\n## Original Description\nPassing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.", "severity": [ { "type": "CVSS_V3", @@ -14,7 +16,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "sqlparse" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.5.0" + } + ] + } + ] + } ], "references": [ { @@ -39,8 +59,8 @@ "CWE-674" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-01T11:08:47Z", "nvd_published_at": "2024-04-30T15:15:53Z" } } \ No newline at end of file