Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38p4-26x2-vqhh

Опубликовано: 06 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

Denial-of-service due to malformed ACL selectors

Impact

An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service.

The problem exists in Redis 7.0.0 or newer.

Patches

The problem is fixed in Redis 7.2.6 and 7.4.1.

Credit

The problem was reported by Axel Mierczuk.

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.2.0, <7.2.6

7.2.6

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.4.0, <7.4.1

7.4.1

EPSS

Процентиль: 33%
0.00398
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 4.4
redhat
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 4.4
nvd
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 4.4
msrc
больше 1 года назад

Denial-of-service due to malformed ACL selectors in Redis

CVSS3: 4.4
debian
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An ...

EPSS

Процентиль: 33%
0.00398
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-20