Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-45145

15
FAUCET Score

CVE-2023-45145 describes a race condition in Redis versions 2.6.0-RC1 through 7.2.1, 7.0.13, and 6.2.13. This vulnerability allows an unauthorized process to establish a connection to Redis via a Unix socket during a brief window on startup if a permissive umask is used. It affects various Redis deployments on Debian and Fedora. The vulnerability has a CVSS score of 3.6 (LOW), indicating a local attack vector with high attack complexity, requiring low privileges, and resulting in limited confidentiality and integrity impact. The EPSS score is low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, aligning with typical patterns for most vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.0, < 6.2.14CPE matchmatch criteria
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
>= 7.0.0, < 7.0.14CPE matchmatch criteria
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
>= 7.2.0, < 7.2.2CPE matchmatch criteria
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
2.6.0CPE matchmatch criteria
cpe:2.3:a:redis:redis:2.6.0:rc1:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.6LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
36.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 91st percentile among its peer group of 223 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 redis 6.2.14-1 on CBL Mariner 2.0Fixed in: 6.2.14-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: redis:7-9050020241104103753.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: redis-0:6.2.17-1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: redis:6-8100020250113083959.489197e6
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-redis6-redis
redhatvendor investigatingvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8

Vendor Advisories (2)

redhatCVE-2023-45145Low

redis: possible bypass of Unix socket permissions on startup

Oct 18, 2023
microsoft2023-Oct/CVE-2023-45145Low

Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.

Oct 10, 2023

References

github.com / redis/redis/commit/03345ddc7faf7af079485f2cbe5d17a1611cbce1
Patch
github.com / redis/redis/security/advisories/GHSA-ghmp-889m-7cvx
Vendor Advisory
lists.debian.org / debian-lts-announce/2023/10/msg00032.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/464JPNBWE433ZGYXO3KN72VR3KJPWHAW
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/BNEK2K4IE7MPKRD6H36JXZMJKYS6I5GQ
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/DZMGTTV5XM4LA66FSIJSETNBBRRPJYOQ
Mailing List
security.netapp.com / advisory/ntap-20231116-0014
Third Party Advisory