cbcvebase.
CVE-2023-45145
published 2023-10-18

CVE-2023-45145: Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided…

PriorityP414low3.6CVSS 3.1
AVLACHPRLUINSUCLILAN
EPSS
0.44%
36.3th percentile
Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianredis< redis 5:7.0.15-1~deb12u1 (bookworm)redis 5:7.0.15-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_redis_6.2.14-1_on_cbl_mariner_2.0
redisredis
redisredis
redisredis
redisredis
redisredis>= 0 < 5:6.0.16-1+deb11u35:6.0.16-1+deb11u3
redisredis>= 0 < 5:7.0.15-1~deb12u15:7.0.15-1~deb12u1
redisredis>= 0 < 5:7.0.14-15:7.0.14-1
redisredis>= 0 < 5:7.0.14-15:7.0.14-1
redisredis>= 0 < 2:2.8.4-2ubuntu0.2+esm32:2.8.4-2ubuntu0.2+esm3
redisredis>= 0 < 2:3.0.6-1ubuntu0.4+esm22:3.0.6-1ubuntu0.4+esm2
redisredis>= 0 < 5:4.0.9-1ubuntu0.2+esm45:4.0.9-1ubuntu0.2+esm4
redisredis>= 0 < 5:5.0.7-2ubuntu0.1+esm25:5.0.7-2ubuntu0.1+esm2
redisredis>= 0 < 5:6.0.16-1ubuntu1+esm15:6.0.16-1ubuntu1+esm1
redisredis>= 2.6.0 < 6.2.146.2.14
redisredis>= 7.0.0 < 7.0.147.0.14
redisredis>= 7.2.0 < 7.2.27.2.2

CVSS provenance

nvdv3.13.6LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
osv8.8HIGH
vendor_ubuntu7.0HIGH
vendor_debian3.6LOW
vendor_msrc3.6LOW
vendor_oracle3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.