`Vulnerability` `CVE-2023-30608` `sqlparse 0.4.3...
# all-things-deployment
c
Vulnerability
CVE-2023-30608
sqlparse 0.4.3
Severity High
Hello team, We got a notification from our security scanner on an issue reported by CWE CVE-2023-30608. I know that it
sqlparse
was kept to 0.4.3 since it was compatible with
sqllinneage
1.3.6. However
sqllinneage
1.3.8 is compatible with 0.4.4, so would it make sense to upgrade sqllinneage to 1.3.8 to avoid the security issue in sqlparse 0.4.3.
d
Hi, thanks for reporting this - we'll deliver this to our core team and get back to you!
c
Thank you so much for the fast response @delightful-ram-75848 🤗
g
c
@gray-shoe-75895 I noticed that the pull request you mentioned got closed because of failing builds. Is it possible to just upgrade it to 1.3.8 since that is just a micro update? 🙂 This will at least get rid of the vulnerability.
a
Sure - doing that here, assuming it passes CI https://github.com/datahub-project/datahub/pull/8481