Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f46f-fjf4-h4m2

Опубликовано: 23 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Redis through 7.4.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions.

Redis through 7.4.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions.

EPSS

Процентиль: 11%
0.00039
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-401
CWE-789

Связанные уязвимости

CVSS3: 3.5
ubuntu
17 дней назад

Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.

CVSS3: 3.5
nvd
17 дней назад

Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.

CVSS3: 3.5
debian
17 дней назад

Redis through 8.0.3 allows memory consumption via a multi-bulk command ...

CVSS3: 4.9
fstec
18 дней назад

Уязвимость системы управления базами данных (СУБД) Redis, связанная с неконтролируемым распределением памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 11%
0.00039
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-401
CWE-789