cbcvebase.
CVE-2023-41053
published 2023-09-06

CVE-2023-41053: Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and as a result may grant users executing…

PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.34%
26.5th percentile
Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. The problem exists in Redis 7.0 or newer and has been fixed in Redis 7.0.13 and 7.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianredis< redis 5:7.0.15-1~deb12u1 (bookworm)redis 5:7.0.15-1~deb12u1 (bookworm)
redisredis
redisredis
redisredis
redisredis>= 0 < 5:7.0.15-1~deb12u15:7.0.15-1~deb12u1
redisredis>= 0 < 5:7.0.13-15:7.0.13-1
redisredis>= 0 < 5:7.0.13-15:7.0.13-1
redisredis>= 7.0 < 7.0.137.0.13

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_oracle3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.