CVE Vulnerabilities

CVE-2016-10517

Published: Oct 24, 2017 | Modified: Aug 08, 2018
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

networking.c in Redis before 3.2.7 allows Cross Protocol Scripting because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

Affected Software

Name Vendor Start Version End Version
Redis Redislabs * 3.2.7 (excluding)
Redis Ubuntu artful *
Redis Ubuntu trusty *
Redis Ubuntu xenial *
Redis Ubuntu zesty *

References