PT-2023-21197 · Kredis · Kredis

Ooooooo_Q

·

Published

2023-06-09

·

Updated

2025-01-09

·

CVE-2023-27531

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kredis versions prior to 1.3.0.1
Description There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This issue may result in the deserialization of unexpected objects in the system when carefully crafted JSON data is processed by Kredis. Any applications using Kredis with JSON are affected.
Recommendations For versions prior to 1.3.0.1, update to version 1.3.0.1 or apply the provided patch for the 1.3.0 series, named 1-3-0-1-kredis.patch, to resolve the issue. As a temporary workaround, consider restricting the use of Kredis with JSON until the update or patch is applied.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-27531
GHSA-H2WM-P2VG-6PW4

Affected Products

Kredis