networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
2017-10-24T18:29:00.197
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9