Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fww-64cx-x8p5

Опубликовано: 26 мар. 2023
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

redis-py Race Condition due to incomplete fix

redis-py through 4.5.3 and 4.4.3 leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a non-pipeline operation), and can send response data to the client of an unrelated request. NOTE: this issue exists because of an incomplete fix for CVE-2023-28858.

Пакеты

Наименование

redis

pip
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.4

4.5.4

Наименование

redis

pip
Затронутые версииВерсия исправления

>= 4.2.0, < 4.4.4

4.4.4

EPSS

Процентиль: 71%
0.00698
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the solutions for CVE-2023-28859 address data leakage across AsyncIO connections in general.

CVSS3: 4.3
redhat
около 2 лет назад

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the solutions for CVE-2023-28859 address data leakage across AsyncIO connections in general.

CVSS3: 6.5
nvd
около 2 лет назад

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the solutions for CVE-2023-28859 address data leakage across AsyncIO connections in general.

CVSS3: 6.5
debian
около 2 лет назад

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open ...

CVSS3: 4.3
fstec
около 2 лет назад

Уязвимость библиотеки Python для Redis redis-py, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 71%
0.00698
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-459