CVE-2023-22458 is a denial-of-service vulnerability affecting Redis versions 6.2 (up to 6.2.9) and 7.0 (up to 7.0.8). Authenticated users can crash Redis by issuing specially crafted HRANDFIELD or ZRANDMEMBER commands, leading to an assertion failure. This vulnerability is rated Medium severity (CVSS 5.5) due to its local attack vector and high impact on availability, with no impact on confidentiality or integrity. There are no known public exploits, Metasploit modules, or significant community discussion surrounding this CVE, and it is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.0, < 6.2.9CPE matchmatch criteria | cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.8CPE matchmatch criteria | cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.