PT-2022-5320 · Redis+1 · Redis+1

J0O1Ey

·

Published

2022-10-28

·

Updated

2024-08-03

·

CVE-2022-3734

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redis (affected versions not specified)
Description A critical vulnerability was found in a port or fork of Redis, affecting the dbghelp.dll library. The issue is related to an uncontrolled search path, which can be exploited remotely. The exploit has been disclosed, but the existence of this vulnerability is still disputed. This issue might affect an unofficial fork or port on Windows only.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2022-06625
BIT-REDIS-2022-3734
CVE-2022-3734

Affected Products

Redis
Dbghelp.Dll