redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response to reports about ChatGPT, and 4.3.6, 4.4.3, and 4.5.3 were released (changing the behavior for pipeline operations); however, please see CVE-2023-28859 about addressing data leakage across AsyncIO connections in general.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-redis | Aug 22, 2024 | Mar 26, 2023 |
| Debian | — | Upgrade python-redis | May 15, 2025 | Mar 26, 2023 |
| Freebsd | — | Upgrade py39-redis | Apr 14, 2023 | Apr 9, 2023 |
| Suse | — | Upgrade python311-sshtunnelUpgrade python311-paramikoUpgrade python311-portalockerUpgrade python311-dockerUpgrade python311-strictyamlUpgrade python311-fakeredisUpgrade python311-frozenlistUpgrade python311-jsondiffUpgrade python311-javapropertiesUpgrade python311-httprettyUpgrade python311-PygmentsUpgrade python311-typing_extensionsUpgrade python311-oauthlibUpgrade python311-pipUpgrade python311-Twisted-tlsUpgrade python311-AutomatUpgrade python311-FabricUpgrade python311-async_timeoutUpgrade python311-asgirefUpgrade python311-multidictUpgrade python311-aiohttpUpgrade python311-sortedcontainersUpgrade python311-Twisted-serialUpgrade python311-chardetUpgrade python311-wraptUpgrade python311-vcrpyUpgrade python311-retryingUpgrade python311-PyJWTUpgrade python311-decoratorUpgrade python311-humanfriendlyUpgrade python311-avroUpgrade python311-scpUpgrade python311-tqdmUpgrade python311-DeprecatedUpgrade python311-pycomposefileUpgrade python311-zope.interfaceUpgrade python311-websocket-clientUpgrade python311-opencensus-ext-threadingUpgrade python311-hyperlinkUpgrade python311-PyGithubUpgrade python311-opencensus-contextUpgrade python311-blinkerUpgrade python311-isodateUpgrade python-paramiko-docUpgrade python311-requests-oauthlibUpgrade python311-aiosignalUpgrade python311-opentelemetry-semantic-conventionsUpgrade python311-Twisted-conch_naclUpgrade python311-lexiconUpgrade python311-pyparsingUpgrade python311-distroUpgrade python311-opentelemetry-apiUpgrade python311-opentelemetry-sdkUpgrade python311-yarlUpgrade python311-wheelUpgrade python311-httplib2Upgrade python311-Twisted-contextvarsUpgrade python311-tabulateUpgrade python311-incrementalUpgrade python311-service_identityUpgrade python311-constantlyUpgrade python-tqdm-bash-completionUpgrade python311-invokeUpgrade python311-zippUpgrade python311-antlr4-python3-runtimeUpgrade python311-pkginfoUpgrade python311-pathspecUpgrade python311-marshmallowUpgrade python311-opencensusUpgrade python311-opentelemetry-test-utilsUpgrade python311-argcompleteUpgrade python311-Twisted-http2Upgrade python311-xmltodictUpgrade python311-knackUpgrade python311-importlib-metadataUpgrade python311-fixedintUpgrade python311-sureUpgrade python311-Twisted-all_non_platformUpgrade python311-semverUpgrade python311-Twisted-conchUpgrade python311-pydashUpgrade python311-TwistedUpgrade python311-fluidity-smUpgrade python311-psutilUpgrade python311-redis | May 15, 2024 | Mar 26, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub