Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-22458

Опубликовано: 20 янв. 2023
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS3: 5.5

Описание

Redis is an in-memory database that persists on disk. Authenticated users can issue a HRANDFIELD or ZRANDMEMBER command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

5:7.0.8-4
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

5:7.0.8-4
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

not-affected

code not present

Показывать по

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
nvd
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
msrc
больше 3 лет назад

Integer overflow in multiple Redis commands can lead to denial-of-service

CVSS3: 5.5
debian
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated us ...

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in the Redis HRANDFIELD and ZRANDMEMBER commands may lead to denial-of-service

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3