Lucene search

K
githubGitHub Advisory DatabaseGHSA-8FWW-64CX-X8P5
HistoryMar 26, 2023 - 9:30 p.m.

redis-py Race Condition due to incomplete fix

2023-03-2621:30:23
CWE-459
GitHub Advisory Database
github.com
12
redis
python
race condition
incomplete fix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

45.7%

redis-py through 4.5.3 and 4.4.3 leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a non-pipeline operation), and can send response data to the client of an unrelated request. NOTE: this issue exists because of an incomplete fix for CVE-2023-28858.

Affected configurations

Vulners
Node
redisredisRange<4.4.4
OR
redisredisRange<4.5.4
CPENameOperatorVersion
redislt4.4.4
redislt4.5.4

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

45.7%