Lucene search

K
cvelistMitreCVELIST:CVE-2023-28859
HistoryMar 26, 2023 - 12:00 a.m.

CVE-2023-28859

2023-03-2600:00:00
mitre
www.cve.org
1
redis-py issue
data leakage
cve-2023-28859

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.7%

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the solutions for CVE-2023-28859 address data leakage across AsyncIO connections in general.

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.7%