Lucene search

K
freebsdFreeBSD3F6D6181-79B2-4D33-BB1E-5D3F9DF0C1D1
HistoryMar 26, 2023 - 12:00 a.m.

py39-redis -- can send response data to the client of an unrelated request

2023-03-2600:00:00
vuxml.freebsd.org
10
py39-redis security issue
incomplete fixes
cve-2023-28859
response data leakage

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

45.7%

drago-balto reports:

redis-py before 4.5.3, as used in ChatGPT and other products, leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a pipeline operation), and can send response data to the client of an unrelated request in an off-by-one manner.
The fixed versions for this CVE Record are 4.3.6, 4.4.3, and 4.5.3, but are believed to be incomplete.
CVE-2023-28859 has been assigned the issues caused by the incomplete fixes.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchpy39-redis< 4.3.6UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

45.7%