redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response to reports about ChatGPT, and 4.3.6, 4.4.3, and 4.5.3 were released (changing the behavior for pipeline operations); however, please see CVE-2023-28859 about addressing data leakage across AsyncIO connections in general.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-redis | Aug 22, 2024 | Mar 26, 2023 |
| Debian | — | Upgrade python-redisNo solution exists | May 15, 2025 | Mar 26, 2023 |
| Freebsd | — | Upgrade py39-redis | Apr 14, 2023 | Apr 9, 2023 |
| Suse | — | Upgrade python311-scpUpgrade python311-opentelemetry-semantic-conventionsUpgrade python311-wraptUpgrade python311-oauthlibUpgrade python311-Twisted-tlsUpgrade python311-Twisted-serialUpgrade python311-Twisted-conch_naclUpgrade python311-pipUpgrade python311-avroUpgrade python311-PygmentsUpgrade python311-async_timeoutUpgrade python311-chardetUpgrade python311-aiohttpUpgrade python311-pycomposefileUpgrade python311-zope.interfaceUpgrade python311-opencensus-ext-threadingUpgrade python311-httprettyUpgrade python311-aiosignalUpgrade python311-asgirefUpgrade python311-AutomatUpgrade python311-tqdmUpgrade python311-lexiconUpgrade python311-decoratorUpgrade python311-FabricUpgrade python311-opencensus-contextUpgrade python311-typing_extensionsUpgrade python311-humanfriendlyUpgrade python311-multidictUpgrade python311-hyperlinkUpgrade python311-DeprecatedUpgrade python311-requests-oauthlibUpgrade python311-retryingUpgrade python311-websocket-clientUpgrade python311-vcrpyUpgrade python311-blinkerUpgrade python311-jsondiffUpgrade python311-PyGithubUpgrade python311-PyJWTUpgrade python311-portalockerUpgrade python311-paramikoUpgrade python311-dockerUpgrade python311-fakeredisUpgrade python311-frozenlistUpgrade python311-sshtunnelUpgrade python311-strictyamlUpgrade python311-sortedcontainersUpgrade python311-isodateUpgrade python311-javapropertiesUpgrade python-paramiko-docUpgrade python311-importlib-metadataUpgrade python311-invokeUpgrade python311-antlr4-python3-runtimeUpgrade python311-opentelemetry-test-utilsUpgrade python311-argcompleteUpgrade python311-Twisted-http2Upgrade python311-pyparsingUpgrade python311-zippUpgrade python311-opentelemetry-sdkUpgrade python311-pydashUpgrade python311-xmltodictUpgrade python311-Twisted-contextvarsUpgrade python311-redisUpgrade python311-yarlUpgrade python311-knackUpgrade python311-sureUpgrade python311-constantlyUpgrade python311-wheelUpgrade python-tqdm-bash-completionUpgrade python311-httplib2Upgrade python311-service_identityUpgrade python311-psutilUpgrade python311-fluidity-smUpgrade python311-tabulateUpgrade python311-Twisted-conchUpgrade python311-Twisted-all_non_platformUpgrade python311-TwistedUpgrade python311-semverUpgrade python311-opentelemetry-apiUpgrade python311-incrementalUpgrade python311-distroUpgrade python311-opencensusUpgrade python311-marshmallowUpgrade python311-pathspecUpgrade python311-fixedintUpgrade python311-pkginfo | May 15, 2024 | Mar 26, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub