-
Notifications
You must be signed in to change notification settings - Fork 336
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GHSA-8fww-64cx-x8p5] redis-py Race Condition due to incomplete fix #2335
[GHSA-8fww-64cx-x8p5] redis-py Race Condition due to incomplete fix #2335
Conversation
Please correct the applicable versions to only 4.x, while 2.x versions are not impacted due to these vulnerabilities.Thanks |
Hey @sreecharanguduri, do you have a reference from the backing project that this issue was fixed in the older branches? I've looked and can't find one. Edit: |
hi again , our team requested NVD to re-access and here is the change history which is updated on May 17th on unimpacted versions here https://nvd.nist.gov/vuln/detail/CVE-2023-28859#VulnChangeHistorySection |
CVE IDs: CVE-2023-28858 and CVE-2023-28859 , Title: "redis: Async command information disclosure" . Basically, data leakage across AsyncIO connections of redis-py library. Async support was not available in "redis-py:2.10.6" version itself. But as part of CVEs scan, these CVE IDs (CVE-2023-28858 and CVE-2023-28859) were raised for redis-py library versions of 2.10.6 . Could you please do update these CVEs starting effected versions above 4.2.x in https://nvd.nist.gov/vuln/detail/CVE-2023-28858 & https://nvd.nist.gov/vuln/detail/CVE-2023-28859. Thank you in advance, and also correct me if i am missing anything. Please contact me if any more details needed. References: |
Ok, found the PR that added async support |
86509d8
into
sreecharanguduri/advisory-improvement-2335
Hi @sreecharanguduri! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
aquasecurity/trivy#4473