PT-2023-21197 · Kredis · Kredis
Ooooooo_Q
·
Published
2023-06-09
·
Updated
2025-01-09
·
CVE-2023-27531
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kredis versions prior to 1.3.0.1
Description
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This issue may result in the deserialization of unexpected objects in the system when carefully crafted JSON data is processed by Kredis. Any applications using Kredis with JSON are affected.
Recommendations
For versions prior to 1.3.0.1, update to version 1.3.0.1 or apply the provided patch for the 1.3.0 series, named 1-3-0-1-kredis.patch, to resolve the issue. As a temporary workaround, consider restricting the use of Kredis with JSON until the update or patch is applied.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kredis