SB2023033020 - Race condition in redis-py
Published: March 30, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2023-28858)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a race condition. A remote attacker can exploit the race and gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/redis/redis-py/compare/v4.3.5...v4.3.6
- https://github.com/redis/redis-py/pull/2641
- https://openai.com/blog/march-20-chatgpt-outage
- https://github.com/redis/redis-py/issues/2624
- https://github.com/redis/redis-py/compare/v4.4.2...v4.4.3
- https://github.com/redis/redis-py/compare/v4.5.2...v4.5.3
- https://github.com/redis/redis-py/releases/tag/v4.5.4
- https://github.com/redis/redis-py/releases/tag/v4.4.4