Improper access control in Redis - CVE-2023-41053

 

Improper access control in Redis - CVE-2023-41053

Published: September 6, 2023


Vulnerability identifier: #VU80512
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41053
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to Redis does not correctly identify keys accessed by SORT_RO. This may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration.


Affected software

Redis
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Server Applications Module
openSUSE Leap
Anolis OS
Fedora
Oracle Communications Cloud Native Core Security Edge Protection Proxy
redis7-debuginfo
redis7-debugsource
redis7
redis
redis-devel
redis-doc
redis (Debian package)
dev-db/redis
Storage Protect Plus Container Agent

How to mitigate CVE-2023-41053

Install updates from vendor's website.

Redis - addressed in versions 7.0.13, 7.2.1
redis7-debuginfo - update to 7.0.8-150500.3.6.1
redis7-debugsource - update to 7.0.8-150500.3.6.1
redis7 - update to 7.0.8-150500.3.6.1
redis - addressed in versions 7.0.13-1.fc37, 7.0.13-1.fc38, 7.2.1-1.fc39
redis - update to 7.0.13-2
redis-devel - update to 7.0.13-2
redis-doc - update to 7.0.13-2
redis (Debian package) - update to 5:7.0.15-1~deb12u1
dev-db/redis - update to 7.2.4
Storage Protect Plus Container Agent - update to 10.1.12.7

External References

Related Security Bulletins