networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
CVSS Details
- CVSS 3.0 Base Score: 7.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade redis | Feb 25, 2019 | Oct 24, 2017 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to version 3.2.7 | Aug 15, 2019 | Oct 24, 2017 |
| Suse | — | Upgrade redis | Nov 10, 2017 | Oct 24, 2017 |
| Ubuntu | — | Upgrade redis | Nov 19, 2024 | Oct 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub