networking.c in Redis before 3.2.7 allows Cross Protocol Scripting because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Redis | Redislabs | * | 3.2.7 (excluding) |
| Redis | Ubuntu | artful | * |
| Redis | Ubuntu | esm-apps/xenial | * |
| Redis | Ubuntu | esm-infra-legacy/trusty | * |
| Redis | Ubuntu | trusty | * |
| Redis | Ubuntu | trusty/esm | * |
| Redis | Ubuntu | xenial | * |
| Redis | Ubuntu | zesty | * |