Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjv8-vjf6-wcr6

Опубликовано: 18 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

HINCRBYFLOAT can be used to crash a redis-server process

Impact

Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that may later crash Redis on access.

Patches

The problem is fixed in Redis versions 7.0.11, 6.2.12 and 6.0.19.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.0.0, <6.0.19

6.0.19

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.12

6.2.12

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.0.0, <7.0.11

7.0.11

EPSS

Процентиль: 58%
0.00963
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-617

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.5
redhat
больше 3 лет назад

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.5
nvd
больше 3 лет назад

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 6.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 3 лет назад

Redis is an open source, in-memory database that persists on disk. Aut ...

EPSS

Процентиль: 58%
0.00963
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-617