← Back to browse · API

CVE-2023-22458

Severity
MEDIUM
CVSS
5.5
EPSS
0.71984
Risk score
47.19
CISA KEV
No
PoC
No
Published
2023-01-20
Modified
2025-03-10
First seen
2026-08-07
Aliases
EUVD-2023-26619
Products
Redis:Redis 6.2, < 6.2.9, Redis:Redis 7.0, < 7.0.8
Sources
euvd EUVD-2023-26619

Description

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References