• CVE-2023-45145

发布时间: 2024年10月12日

修改时间: 2024年10月18日

概要

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.

CVSS v3 指标

NVD openEuler
CVSS评分 3.6 3.6
Attack Vector Local Local
Attack Complexity High High
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Low Low
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4067 redis security update 2024年10月18日
KylinSec-SA-2024-4081 redis security update 2024年10月12日

影响产品

产品 状态
KY3.4-5A redis Fixed
KY3.5.2 redis Fixed
V6 redis Fixed