Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prpq-rh5h-46g9

Опубликовано: 06 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

Denial-of-service due to malformed ACL selectors

Impact

An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service.

The problem exists in Redis 7.0.0 or newer.

Patches

The problem is fixed in Redis 7.2.7 and 7.4.2.

Credit

The problem was reported by Axel Mierczuk.

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.2.0, <7.2.7

7.2.7

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.4.0, <7.4.2

7.4.2

EPSS

Процентиль: 22%
0.00299
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 1 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
redhat
больше 1 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
nvd
больше 1 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
msrc
5 месяцев назад

Redis allows denial-of-service due to malformed ACL selectors

CVSS3: 4.4
debian
больше 1 года назад

Redis is an open source, in-memory database that persists on disk. An ...

EPSS

Процентиль: 22%
0.00299
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-20