Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-28425: Specially crafted MSETNX command can lead to denial-of-service

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.

CVE
#dos#redis#auth

Moderate

oranagra published GHSA-mvmm-4vq6-vw8c

Mar 20, 2023

Affected versions

>= 7.0.8

Description

Impact

Authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process.

Patches

The problem is fixed in Redis versions 7.0.10.

Credit

The issue has been identified by Yupeng Yang.

For more information

If you have any questions or comments about this advisory:

Severity

CVSS base metrics

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Related news

Gentoo Linux Security Advisory 202408-05

Gentoo Linux Security Advisory 202408-5 - Multiple vulnerabilities have been discovered in Redis, the worst of which may lead to a denial of service or possible remote code execution. Versions greater than or equal to 7.2.4 are affected.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907