dbt uses a SQLparse version with a high vulnerability
High7.5Published Apr 22, 2024 · updated Dec 5, 2024
### Summary Using a version of `sqlparse` that has a security vulnerability and no way to update in current version of dbt core. Snyk recommends using `sqlparse==0.5` but this causes a conflict with dbt. Snyk states the issues is a recursion error: `SNYK-PYTHON-SQLPARSE-6615674`. ### Details Dependency conflict error message: ```sh The conflict is caused by: The user requested sqlparse==0.5 dbt-core 1.7.10 depends on sqlparse<0.5 and >=0.2.3 ``` Resolution was to pin `sqlparse >=0.5.0, <0.6.0` in `dbt-core`, patched in 1.6.13 and 1.7.13. ### PoC From Snyk: ```python import sqlparse sqlparse.parse('[' * 10000 + ']' * 10000) ``` ### Impact Snyk classifies it as high 7.5/10. ### Patches The bug has been fixed in [dbt-core v1.6.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.6.13) and [dbt-core v1.7.13](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.13). ### Mitigations Bump `dbt-core` 1.6 and 1.7 dependencies to 1.6.13 and 1.7.13 respectively
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dbt-core PyPI | >= 1.6.0, < 1.6.13 | 1.6.13 |
| >= 1.7.0, < 1.7.13 | 1.7.13 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-673
More dbt Core advisories
All dbt Core| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 172024 | dbt has an implicit override for built-in materializations from installed packages | Low4.2 | 1.6.14+1 more |
| May 282024 | dbt allows Binding to an Unrestricted IP Address via socketsocket | Medium5.3 | 1.6.15+2 more |
| Dec 82023 | dbt-core's secret env vars written to package-lock.json in plaintext | Low3.2 | 1.7.3 |