« Volver al listado

CVE-2023-28858

Estado: ModificadaBaja (3.7)—

redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response to reports about ChatGPT, and 4.3.6, 4.4.3, and 4.5.3 were released (changing the behavior for pipeline operations); however, please see CVE-2023-28859 about addressing data leakage across AsyncIO connections in general.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-28858",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-28858",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-20T15:35:20.640859Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-03-26T19:15:06.780",
  "references": [
    {
      "url": "https://github.com/redis/redis-py/compare/v4.3.5...v4.3.6",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/redis/redis-py/compare/v4.4.2...v4.4.3",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/redis/redis-py/compare/v4.5.2...v4.5.3",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/redis/redis-py/issues/2624",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/redis/redis-py/pull/2641",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://openai.com/blog/march-20-chatgpt-outage",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/redis/redis-py/compare/v4.3.5...v4.3.6",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/redis/redis-py/compare/v4.4.2...v4.4.3",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/redis/redis-py/compare/v4.5.2...v4.5.3",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/redis/redis-py/issues/2624",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/redis/redis-py/pull/2641",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://openai.com/blog/march-20-chatgpt-outage",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-193"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response to reports about ChatGPT, and 4.3.6, 4.4.3, and 4.5.3 were released (changing the behavior for pipeline operations); however, please see CVE-2023-28859 about addressing data leakage across AsyncIO connections in general."
    }
  ],
  "lastModified": "2026-06-17T05:48:55.853",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01B96893-5078-47C0-A2F2-D1039A45152D",
              "versionEndExcluding": "4.3.6",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4512975-5839-4179-9B9E-526526E02C6F",
              "versionEndExcluding": "4.4.3",
              "versionStartIncluding": "4.4.0"
            },
            {
              "criteria": "cpe:2.3:a:redis:redis-py:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5782D240-CF0F-41B0-9A06-47DD9E51C075",
              "versionEndExcluding": "4.5.3",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}