Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r965-fhrj-6v64

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

EPSS

Процентиль: 81%
0.02147
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 9 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 5.3
redhat
около 10 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 7.4
nvd
почти 9 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 7.4
debian
почти 9 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" b ...

CVSS3: 7.4
fstec
почти 9 лет назад

Уязвимость компонента networking.c системы управления базами данных (СУБД) Redis, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 81%
0.02147
Низкий

7.4 High

CVSS3