Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-28425
HistoryMar 20, 2023 - 8:15 p.m.

Command injection

2023-03-2020:15:00
PRIOn knowledge base
www.prio-n.com
13
redis
command injection
authentication bypass
server process
msetnx command
security vulnerability
patch

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.

CPENameOperatorVersion
redisge7.0.8
redislt7.0.10

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%