Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-22458

Опубликовано: 20 янв. 2023
Источник: nvd
CVSS3: 5.5
EPSS Высокий

Описание

Redis is an in-memory database that persists on disk. Authenticated users can issue a HRANDFIELD or ZRANDMEMBER command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 6.2.0 (включая) до 6.2.9 (исключая)
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.8 (исключая)

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
redhat
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
msrc
больше 3 лет назад

Integer overflow in multiple Redis commands can lead to denial-of-service

CVSS3: 5.5
debian
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated us ...

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in the Redis HRANDFIELD and ZRANDMEMBER commands may lead to denial-of-service

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3

Дефекты

CWE-190
CWE-190