networking.c in Redis before 3.2.7 allows Cross Protocol Scripting because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Redis | Redislabs | * | 3.2.7 (excluding) |
Redis | Ubuntu | artful | * |
Redis | Ubuntu | trusty | * |
Redis | Ubuntu | xenial | * |
Redis | Ubuntu | zesty | * |