Описание
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the HINCRBYFLOAT
command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.
A vulnerability was found in Redis. This flaw allows authenticated users to use the HINCRBYFLOAT command to create an invalid hash field that may crash Redis on access.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat 3scale API Management Platform 2 | 3scale-amp-backend-container | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Affected | ||
Red Hat Ansible Automation Platform 1.2 | ansible-tower | Not affected | ||
Red Hat Enterprise Linux 9 | redis | Will not fix | ||
Red Hat Fuse 7 | redis | Not affected | ||
Red Hat OpenStack Platform 13 (Queens) | redis | Out of support scope | ||
Red Hat Quay 3 | quay/quay-rhel8 | Affected | ||
Red Hat Satellite 6 | satellite:el8/rubygem-gitlab-sidekiq-fetcher | Not affected | ||
Red Hat Software Collections | rh-redis6-redis | Will not fix | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | acm-governance-policy-addon-controller-container | Fixed | RHSA-2023:3326 | 26.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed in in versions 7.0.11, 6.2.12, and 6.0.19. Users are advised to upgrade. There are no known workarounds for this issue.
Redis is an open source, in-memory database that persists on disk. Aut ...
EPSS
5.5 Medium
CVSS3