Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-47004

Опубликовано: 07 нояб. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

An out-of-bounds write flaw was found in RedisGraph, a module for the Redis server, due to improper code logic after a valid authentication. This issue may lead to arbitrary code execution.

Отчет

The default security model [1] for Redis servers dictates that deployments should be made in trusted environments and accessed by trusted clients. Therefore, using the default model, an attacker should only be able to trigger this vulnerability through adjacent networks after compromise of internal access controls. [1] https://redis.io/docs/management/security/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/redisgraph-tls-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2248509redisgraph: Out of bounds write due to improper code logic after a valid authentication

EPSS

Процентиль: 68%
0.00557
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

CVSS3: 8.8
github
больше 2 лет назад

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость графовой базы данных RedisGraph, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 68%
0.00557
Низкий

7.5 High

CVSS3