CVE-2023-22458
medium · 5.5Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
5.5
CVSS
72.0%
EPSS (exploit prob.)
99th
EPSS percentile
2023-01-20
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-190
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redis | redis | >= 6.2.0, < 6.2.9 |
| redis | redis | >= 7.0.0, < 7.0.8 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/redis/redis/commit/16f408b1a0121cacd44cbf8aee275d69dc627f02
- https://github.com/redis/redis/releases/tag/6.2.9
- https://github.com/redis/redis/releases/tag/7.0.8
- https://github.com/redis/redis/security/advisories/GHSA-r8w2-2m53-gprj
- https://github.com/redis/redis/commit/16f408b1a0121cacd44cbf8aee275d69dc627f02
- https://github.com/redis/redis/releases/tag/6.2.9
- https://github.com/redis/redis/releases/tag/7.0.8
- https://github.com/redis/redis/security/advisories/GHSA-r8w2-2m53-gprj
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-22458