Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q32-c38c-pwgq

Опубликовано: 06 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Redis DoS Vulnerability due to bad connection error handling

Impact

An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service.

The problem affects all versions of Redis.

Patches

The problem is fixed in Redis 6.2.X, 7.2.X, 7.4.X and 8.0.X

Credit

The problem was reported by @julienperriercornet

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.19

6.2.19

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.2.0, <7.2.10

7.2.10

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.4.0, <7.4.5

7.4.5

Наименование

redis

redis
Затронутые версииВерсия исправления

>=8.0.0, <8.0.3

8.0.3

EPSS

Процентиль: 50%
0.00733
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

CVSS3: 5.3
redhat
около 1 года назад

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

CVSS3: 7.5
nvd
около 1 года назад

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to client starvation and, ultimately, a denial of service. This vulnerability is fixed in 8.0.3, 7.4.5, 7.2.10, and 6.2.19.

CVSS3: 7.5
msrc
около 1 года назад

Redis DoS Vulnerability due to bad connection error handling

CVSS3: 7.5
debian
около 1 года назад

Redis is an open source, in-memory database that persists on disk. An ...

EPSS

Процентиль: 50%
0.00733
Низкий

7.5 High

CVSS3

Дефекты

CWE-770