Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-41056

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.051
EPSS Ranking 89.4%
CVSS Severity
CVSS v3 Score 8.1
References
Products affected by CVE-2023-41056
  • Redis » Redis » Version: 7.0.10
    cpe:2.3:a:redis:redis:7.0.10
  • Redis » Redis » Version: 7.0.11
    cpe:2.3:a:redis:redis:7.0.11
  • Redis » Redis » Version: 7.0.12
    cpe:2.3:a:redis:redis:7.0.12
  • Redis » Redis » Version: 7.0.13
    cpe:2.3:a:redis:redis:7.0.13
  • Redis » Redis » Version: 7.0.14
    cpe:2.3:a:redis:redis:7.0.14
  • Redis » Redis » Version: 7.0.9
    cpe:2.3:a:redis:redis:7.0.9
  • Redis » Redis » Version: 7.2.0
    cpe:2.3:a:redis:redis:7.2.0
  • Redis » Redis » Version: 7.2.1
    cpe:2.3:a:redis:redis:7.2.1
  • Redis » Redis » Version: 7.2.2
    cpe:2.3:a:redis:redis:7.2.2
  • Redis » Redis » Version: 7.2.3
    cpe:2.3:a:redis:redis:7.2.3
  • Fedoraproject » Fedora » Version: 38
    cpe:2.3:o:fedoraproject:fedora:38
  • Fedoraproject » Fedora » Version: 39
    cpe:2.3:o:fedoraproject:fedora:39


Contact Us

Shodan ® - All rights reserved