PT-2023-2097 · Pypi+3 · Redis-Py+3

Drago-Balto

·

Publicado

2023-03-26

·

Atualizado

2024-07-01

·

CVE-2023-28858

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions redis-py versions prior to 4.5.3
Description The issue is related to the redis-py library, which leaves a connection open after canceling an async Redis command at an inopportune time, specifically in the case of a pipeline operation. This can cause response data to be sent to the client of an unrelated request in an off-by-one manner, potentially allowing a remote attacker to gain unauthorized access to protected information. The library is used in products such as ChatGPT.
Recommendations For redis-py versions prior to 4.5.3, update to version 4.5.3 or later to resolve the issue. However, note that the fixed versions 4.3.6, 4.4.3, and 4.5.3 may be incomplete, and additional issues may be addressed in separate vulnerabilities. As a temporary workaround, consider restricting the use of pipeline operations until a more comprehensive fix is available.

Exploit

Correção

Race Condition

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01831
CVE-2023-28858
GHSA-24WV-MV5M-XV4H
OPENSUSE-SU-2024:12873-1
OPENSUSE-SU-2024_1639-1
OPENSUSE-SU-2024_1639-2
PYSEC-2023-45
SUSE-SU-2024:1639-1
SUSE-SU-2024:1639-2
SUSE-SU-2024_1639-1
SUSE-SU-2024_1639-2

Produtos afetados

Debian
Red Os
Suse
Redis-Py