Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28425


Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.


Published

2023-03-20T20:15:52.787

Last Modified

2024-11-21T07:55:02.423

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redis redis < 7.0.10 Yes

References