PT-2020-17382 · Redis · Redisgraph
Cr0Hn
·
Published
2020-12-23
·
Updated
2020-12-28
·
CVE-2020-35668
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RedisGraph versions 2.x through 2.2.11
Description
The issue is related to a NULL Pointer Dereference that can cause a server crash. This occurs because the software mishandles an unquoted string, such as an alias that has not yet been introduced.
Recommendations
For RedisGraph versions 2.x through 2.2.11, consider updating to a version later than 2.2.11 to resolve the issue. As a temporary workaround, consider restricting the use of unquoted strings, such as aliases that have not yet been introduced, to minimize the risk of server crashes.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redisgraph