CVE-2023-28858 affects redis-py versions prior to 4.5.3, where an improperly closed connection after canceling an async Redis command can lead to response data from one request being sent to an unrelated client. This vulnerability has a low CVSS score of 3.7, indicating a network-based attack with high complexity, but only results in a low impact on confidentiality. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.3.6CPE matchmatch criteria | cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.3CPE matchmatch criteria | cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:* | ||
>= 4.5.0, < 4.5.3CPE matchmatch criteria | cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.