redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the solutions for CVE-2023-28859 address data leakage across AsyncIO connections in general.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-redis | Aug 22, 2024 | Mar 26, 2023 |
| Freebsd | — | Upgrade py39-redis | Apr 14, 2023 | Apr 9, 2023 |
| Suse | — | Upgrade python311-wheelUpgrade python311-chardetUpgrade python311-requests-oauthlibUpgrade python311-marshmallowUpgrade python311-opentelemetry-semantic-conventionsUpgrade python311-portalockerUpgrade python311-strictyamlUpgrade python311-retryingUpgrade python311-AutomatUpgrade python311-multidictUpgrade python311-vcrpyUpgrade python311-wraptUpgrade python311-blinkerUpgrade python311-scpUpgrade python311-tqdmUpgrade python311-sshtunnelUpgrade python311-TwistedUpgrade python311-pkginfoUpgrade python311-httplib2Upgrade python311-typing_extensionsUpgrade python311-pycomposefileUpgrade python311-dockerUpgrade python311-paramikoUpgrade python311-sortedcontainersUpgrade python311-oauthlibUpgrade python311-asgirefUpgrade python311-psutilUpgrade python311-zippUpgrade python-paramiko-docUpgrade python311-aiohttpUpgrade python311-websocket-clientUpgrade python311-tabulateUpgrade python311-zope.interfaceUpgrade python311-constantlyUpgrade python311-pipUpgrade python311-opentelemetry-test-utilsUpgrade python311-Twisted-contextvarsUpgrade python311-isodateUpgrade python311-knackUpgrade python311-semverUpgrade python311-hyperlinkUpgrade python311-Twisted-serialUpgrade python311-PygmentsUpgrade python311-antlr4-python3-runtimeUpgrade python311-FabricUpgrade python311-fixedintUpgrade python311-lexiconUpgrade python311-service_identityUpgrade python311-opentelemetry-apiUpgrade python311-pydashUpgrade python311-Twisted-tlsUpgrade python311-avroUpgrade python311-decoratorUpgrade python311-opentelemetry-sdkUpgrade python311-PyJWTUpgrade python311-javapropertiesUpgrade python311-incrementalUpgrade python-tqdm-bash-completionUpgrade python311-humanfriendlyUpgrade python311-pathspecUpgrade python311-sureUpgrade python311-yarlUpgrade python311-DeprecatedUpgrade python311-httprettyUpgrade python311-invokeUpgrade python311-frozenlistUpgrade python311-opencensus-contextUpgrade python311-redisUpgrade python311-fluidity-smUpgrade python311-fakeredisUpgrade python311-argcompleteUpgrade python311-distroUpgrade python311-Twisted-conchUpgrade python311-Twisted-all_non_platformUpgrade python311-opencensusUpgrade python311-jsondiffUpgrade python311-importlib-metadataUpgrade python311-pyparsingUpgrade python311-async_timeoutUpgrade python311-Twisted-http2Upgrade python311-xmltodictUpgrade python311-opencensus-ext-threadingUpgrade python311-PyGithubUpgrade python311-Twisted-conch_naclUpgrade python311-aiosignal | May 15, 2024 | Mar 26, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub