Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28856

Опубликовано: 18 апр. 2023
Источник: nvd
CVSS3: 5.5
CVSS3: 6.5
EPSS Низкий

Описание

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия до 6.0.19 (исключая)
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 6.2.0 (включая) до 6.2.12 (исключая)
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.11 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00133
Низкий

5.5 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-617

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.5
redhat
около 2 лет назад

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 6.5
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 2 лет назад

Redis is an open source, in-memory database that persists on disk. Aut ...

CVSS3: 6.5
redos
около 2 лет назад

Уязвимость Redis

EPSS

Процентиль: 34%
0.00133
Низкий

5.5 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-617