BDU:2023-03474BDU:2023-03474HIGH7.4Уязвимость компонента networking.c системы управления базами данных (СУБД) Redis, позволяющая нарушителю получить доступ к конфиденциальным даннымОпубликовано: 2023-06-30CVSS 3.xВЫСОКАЯ 7.4CVSS:3.x/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NCVSS 2.0ВЫСОКАЯ 7.8CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:N/A:NСсылкиCVE-2016-10517
CVE-2016-10517CVE-2016-10517HIGH7.4networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).Опубликовано: 2017-10-24Изменено: 2025-04-20CVSS 2.0СРЕДНЯЯ 4.3CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:NCVSS 3.xВЫСОКАЯ 7.4CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NСсылкиhttp://www.securityfocus.com/bid/101572https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTEShttps://www.reddit.com/r/redis/comments/5r8wxn/redis_327_is_out_important_security_fixes_inside/http://www.securityfocus.com/bid/101572https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTEShttps://www.reddit.com/r/redis/comments/5r8wxn/redis_327_is_out_important_security_fixes_inside/