Improper access control in Redis - CVE-2023-41053
Published: September 6, 2023
Vulnerability identifier: #VU80512
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41053
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to Redis does not correctly identify keys accessed by SORT_RO. This may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration.
Affected software
Redis
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Server Applications Module
openSUSE Leap
Anolis OS
Fedora
Oracle Communications Cloud Native Core Security Edge Protection Proxy
redis7-debuginfo
redis7-debugsource
redis7
redis
redis-devel
redis-doc
redis (Debian package)
dev-db/redis
Storage Protect Plus Container Agent
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Server Applications Module
openSUSE Leap
Anolis OS
Fedora
Oracle Communications Cloud Native Core Security Edge Protection Proxy
redis7-debuginfo
redis7-debugsource
redis7
redis
redis-devel
redis-doc
redis (Debian package)
dev-db/redis
Storage Protect Plus Container Agent
How to mitigate CVE-2023-41053
Install updates from vendor's website.
Redis - addressed in versions 7.0.13, 7.2.1
redis7-debuginfo - update to 7.0.8-150500.3.6.1
redis7-debugsource - update to 7.0.8-150500.3.6.1
redis7 - update to 7.0.8-150500.3.6.1
redis - addressed in versions 7.0.13-1.fc37, 7.0.13-1.fc38, 7.2.1-1.fc39
redis - update to 7.0.13-2
redis-devel - update to 7.0.13-2
redis-doc - update to 7.0.13-2
redis (Debian package) - update to 5:7.0.15-1~deb12u1
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.7
redis7-debuginfo - update to 7.0.8-150500.3.6.1
redis7-debugsource - update to 7.0.8-150500.3.6.1
redis7 - update to 7.0.8-150500.3.6.1
redis - addressed in versions 7.0.13-1.fc37, 7.0.13-1.fc38, 7.2.1-1.fc39
redis - update to 7.0.13-2
redis-devel - update to 7.0.13-2
redis-doc - update to 7.0.13-2
redis (Debian package) - update to 5:7.0.15-1~deb12u1
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.7
External References
Related Security Bulletins
- Improper acces control in Redis
- Fedora 39 update for redis
- Fedora 38 update for redis
- Fedora 37 update for redis
- SUSE update for redis7
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Debian update for redis
- Gentoo update for Redis
- Red Hat Enterprise Linux 9 update for the redis:7 module
- Anolis OS update for redis