PT-2023-21197 · Kredis · Kredis

Ooooooo_Q

·

Publicado

2023-06-09

·

Atualizado

2025-01-09

·

CVE-2023-27531

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kredis versions prior to 1.3.0.1
Description There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This issue may result in the deserialization of unexpected objects in the system when carefully crafted JSON data is processed by Kredis. Any applications using Kredis with JSON are affected.
Recommendations For versions prior to 1.3.0.1, update to version 1.3.0.1 or apply the provided patch for the 1.3.0 series, named 1-3-0-1-kredis.patch, to resolve the issue. As a temporary workaround, consider restricting the use of Kredis with JSON until the update or patch is applied.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27531
GHSA-H2WM-P2VG-6PW4

Produtos afetados

Kredis