Lucene search

K

Redis Security Vulnerabilities

cve
cve

CVE-2023-41053

Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by SORT_RO and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. The problem exists in Redis 7.0 or newer and has been f...

3.3CVSS

4AI Score

0.0004EPSS

2023-09-06 09:15 PM
318
cve
cve

CVE-2023-41056

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

8.1CVSS

8.3AI Score

0.007EPSS

2024-01-10 04:15 PM
128
cve
cve

CVE-2023-45145

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process...

3.6CVSS

3.8AI Score

0.0004EPSS

2023-10-18 09:15 PM
225
Total number of security vulnerabilities53