CVE-2023-42809 is a critical deserialization vulnerability affecting Redisson, a Java Redis client, prior to version 3.22.0. Attackers can exploit this by tricking clients into connecting to a malicious Redis server, which then sends specially crafted Java objects that, upon deserialization, execute arbitrary code on the client's machine. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low complexity, requiring user interaction, and leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.22.0CPE matchmatch criteria | cpe:2.3:a:redisson:redisson:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.