Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6935-g2xg-qvf4

Опубликовано: 22 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation vulnerability in Apache Kvrocks.

The SETRANGE command didn't check if the offset input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1.

Users are recommended to upgrade to version 2.12.0, which fixes the issue.

Improper Input Validation vulnerability in Apache Kvrocks.

The SETRANGE command didn't check if the offset input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1.

Users are recommended to upgrade to version 2.12.0, which fixes the issue.

EPSS

Процентиль: 59%
0.00381
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is  out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to upgrade to version 2.12.0, which fixes the issue.

EPSS

Процентиль: 59%
0.00381
Низкий

7.5 High

CVSS3

Дефекты

CWE-20