← Back

CVE-2023-45145

nvd nist
Published: Oct 18, 2023Modified: Jun 17, 2026

JSON object

Loading...
3.6
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.0 / Impact: 2.5
Source: NVD

Description

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.

Affected (8)

1 product
Redis
1 product
Fedora
1 product
Debian Linux
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Redis
From 2.6.0 to 6.2.14
From 7.0.0 to 7.0.14
From 7.2.0 to 7.2.2
Version 2.6.0 rc1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 37
Version 38
Version 39
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (14)

Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.