CVE-2023-22458
CVSS V2 None
CVSS V3 None
Description
Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Overview
- CVE ID
- CVE-2023-22458
- Assigner
- security-advisories@github.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-01-20T19:15:17
- Last Modified Date
- 2023-02-02T14:23:40
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | 1 | OR | 6.2.0 | 6.2.9 |
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | 1 | OR | 7.0.0 | 7.0.8 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-22458 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22458 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-01-20 21:14:27 | Added to TrackCVE | |||
2023-01-20 21:14:29 | Weakness Enumeration | new | ||
2023-01-23 15:14:25 | 2023-01-23T15:08:08 | CVE Modified Date | updated | |
2023-01-23 15:14:25 | Received | Awaiting Analysis | Vulnerability Status | updated |
2023-01-31 13:14:25 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-02-02 15:14:47 | 2023-02-02T14:23:40 | CVE Modified Date | updated | |
2023-02-02 15:14:47 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-02-02 15:14:49 | CPE Information | updated |