#1041428 sqlfluff: CVE-2023-36830

Package:
src:sqlfluff
Source:
src:sqlfluff
Submitter:
Moritz Mühlenhoff
Date:
2024-02-22 20:06:04 UTC
Severity:
normal
Tags:
#1041428#5
Date:
2023-07-18 18:49:04 UTC
From:
To:
Hi,

The following vulnerability was published for sqlfluff.

CVE-2023-36830[0]:
| SQLFluff is a SQL linter. Prior to version 2.1.2, in environments
| where untrusted users have access to the config files, there is a
| potential security vulnerability where those users could use the
| `library_path` config value to allow arbitrary python code to be
| executed via macros. For many users who use SQLFluff in the context
| of an environment where all users already have fairly escalated
| privileges, this may not be an issue - however in larger user bases,
| or where SQLFluff is bundled into another tool where developers
| still wish to give users access to supply their on rule
| configuration, this may be an issue.  The 2.1.2 release offers the
| ability for the `library_path` argument to be overwritten on the
| command line by using the `--library-path` option. This overrides
| any values provided in the config files and effectively prevents
| this route of attack for users which have access to the config file,
| but not to the scripts which call the SQLFluff CLI directly. A
| similar option is provided for the Python API, where users also have
| a greater ability to further customise or override configuration as
| necessary. Unless `library_path` is explicitly required, SQLFluff
| maintainers recommend using the option `--library-path none` when
| invoking SQLFluff which will disable the `library-path` option
| entirely regardless of the options set in the configuration file or
| via inline config directives. As a workaround, limiting access to -
| or otherwise validating configuration files before they are ingested
| by SQLFluff will provides a similar effect and does not require
| upgrade.

https://github.com/sqlfluff/sqlfluff/security/advisories/GHSA-jqhc-m2j3-fjrx
https://github.com/sqlfluff/sqlfluff/pull/4925


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-36830
https://www.cve.org/CVERecord?id=CVE-2023-36830

Please adjust the affected versions in the BTS as needed.

#1041428#16
Date:
2024-02-22 09:24:00 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
sqlfluff, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1041428@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Tille <tille@debian.org> (supplier of updated sqlfluff package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 22 Feb 2024 08:28:45 +0100
Source: sqlfluff
Architecture: source
Version: 2.3.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Andreas Tille <tille@debian.org>
Closes: 1041428 1056532
Changes:
 sqlfluff (2.3.5-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream version
     Closes: #1041428 (CVE-2023-36830)
     Closes: #1056532
   * Add upstream metadata
Checksums-Sha1:
 f41caef5560b3100a744298ea0be010269ed2aed 3617 sqlfluff_2.3.5-1.dsc
 40304c3f5e92b321398c9f44bb73148329031dfe 2039182 sqlfluff_2.3.5.orig.tar.gz
 2a06d8e708d30eb21455b0957334b4d1020fb172 8660 sqlfluff_2.3.5-1.debian.tar.xz
 e8df917036864391947f7c11a7003639a09f35f2 8559 sqlfluff_2.3.5-1_amd64.buildinfo
Checksums-Sha256:
 c4fea16961f9dfb3fc58c915dc6e53bfd49e810d1b8bcb6f4ac292d8241ac5b4 3617 sqlfluff_2.3.5-1.dsc
 85d7cb5cbe0e2fb0745593a0543f35315389bce004481efde7e6d3ae7338f12f 2039182 sqlfluff_2.3.5.orig.tar.gz
 e219b625ae7e5bcb5f1bd3981e453936969bfa66bcb246275e236a58e851ec73 8660 sqlfluff_2.3.5-1.debian.tar.xz
 4e8e54ff29df6a54c8132420ebe222e19debd39c6d18d0877cfb9e54986afb36 8559 sqlfluff_2.3.5-1_amd64.buildinfo
Files:
 3b1ce342c004d4e2582f4e9c97932677 3617 python optional sqlfluff_2.3.5-1.dsc
 a4f03900bb5c42bae2f9c600092c0af4 2039182 python optional sqlfluff_2.3.5.orig.tar.gz
 27a0c9fe431f16b94c74c80141c027f0 8660 python optional sqlfluff_2.3.5-1.debian.tar.xz
 5d0839703f84a50761682a714ea8a25b 8559 python optional sqlfluff_2.3.5-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEE8fAHMgoDVUHwpmPKV4oElNHGRtEFAmXW/jQRHHRpbGxlQGRl
Ymlhbi5vcmcACgkQV4oElNHGRtEYcQ/9HhEDZm4MRvScqf8sqiP136slhpg84I3u
SCPvR+1i/hTisu8xdpNLT4PYHNrIXRCtJoGRzZQUGg8vyM3aQDisB3GgTOT841bH
mqrrt0tArTZeZAYzUiNJHsEXaBHqwF8aNPSqnGdgVW1e0hdeVOQJJzvHC1yaWVyl
pv/K0UeT1ZbVHnXSGM0Npq2pQcivJr1z2q2Aox3GAfTtTkTfJwLN5j6e7gp/es0r
J57LhIINPlzIX8D6v17uRBkCVVtuRYar6ZzRkujm39AQGhD1V05kXOZ26+vq+wmH
YxEUWUozyzMryM1qaLUDpQu/SQgzsVAeX9n0k+L6OtyniwgLkVygM2otxyejDZTs
PgIGRDaeWcPwzX+vv40yC9dspEngcXEsVyjj7ZcPfc3tmzZdcEtVMBcZ2eLJrSEC
IpbYAp1oMoRG6rQGGfuF762oEQfkMpVugmhqU/G9s3UjCOeX77OzYSrjkclRy/ZS
HGOJ3a7wTIf3pU++34ITpTCosS5sXNuvFNbfXVbGKBYcmk7OdICzqpU3rA8tkgS6
MsblERKKQVwRRs1TAufSwfXXPXGtlTdP/mrJVYJZoj/sMOvp4D77Qu15ETUQ1fPt
eW0E8vy4evZoigLjwlPUrU5wQh6h5L5FR82sz8zaAVNXxzAZckxMD+EVWCl1Bg4o
6mlqerLwiaA=
=DKzi
-----END PGP SIGNATURE-----