Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r965-fhrj-6v64

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

EPSS

Процентиль: 51%
0.00275
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 8 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 5.3
redhat
больше 9 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 7.4
nvd
больше 8 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

CVSS3: 7.4
debian
больше 8 лет назад

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" b ...

CVSS3: 7.4
fstec
больше 8 лет назад

Уязвимость компонента networking.c системы управления базами данных (СУБД) Redis, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 51%
0.00275
Низкий

7.4 High

CVSS3