Lucene search

K
freebsdFreeBSD6C72B13F-4D1D-11EE-A7F1-080027F5FEC9
HistorySep 06, 2023 - 12:00 a.m.

redis -- Possible bypassing ACL configuration

2023-09-0600:00:00
vuxml.freebsd.org
11
redis
acl
bypass

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.0004 Low

EPSS

Percentile

15.5%

yangbodong22011 reports:

    Redis does not correctly identify keys accessed by SORT_RO
    and, as a result, may grant users executing this command
    access to keys that are not explicitly authorized by the
    ACL configuration.

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.0004 Low

EPSS

Percentile

15.5%