Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in Redis version 7.0.10.
References
Configurations
History
13 Apr 2023, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-77 | |
| References |
|
Information
Published : 2023-03-20 20:15
Updated : 2023-04-13 17:15
NVD link : CVE-2023-28425
Mitre link : CVE-2023-28425
JSON object : View
Products Affected
redis
- redis
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
