networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
[ { "target": { "file": "src/server.c" }, "source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50", "signature_type": "Line", "id": "CVE-2016-10517-34fc378b", "signature_version": "v1", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "124880604520077166671741876553448855320", "17607989238585627192006328325640026296", "316040378880908604113778517788260677767", "93458149514543909809984600211885125528" ] } }, { "target": { "file": "src/server.h" }, "source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50", "signature_type": "Line", "id": "CVE-2016-10517-8b5e18a9", "signature_version": "v1", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "293441393269233123675708999680469895646", "70362983986487224871491241103974749383", "205390326808090795749215624981622578027", "304632248323533289008649620454653853583" ] } }, { "target": { "file": "src/networking.c" }, "source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50", "signature_type": "Line", "id": "CVE-2016-10517-c30ff40c", "signature_version": "v1", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "163148284592519125185901164272060612753", "70451653832058093279536878907119473300", "215185346124952849263144259165636240912", "100079807825566757584135242790465355990", "199479240253159866632050854038291740593", "245006625046125700008417689478308844302", "96178466864819807631888675772326466251" ] } }, { "target": { "function": "processInputBuffer", "file": "src/networking.c" }, "source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50", "signature_type": "Function", "id": "CVE-2016-10517-f00326f7", "signature_version": "v1", "deprecated": false, "digest": { "function_hash": "152124302612145123004825358630729190358", "length": 876.0 } } ]