PYSEC-2023-312

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/redis/PYSEC-2023-312.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2023-312
Withdrawn
2025-06-09T16:52:30Z
Published
2023-07-15T23:15:09Z
Modified
2025-10-09T07:42:21.654379Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.

References

Affected packages

PyPI / redis

Package

Affected ranges

Type
GIT
Repo
https://github.com/redis/redis
Events
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.2.0

Affected versions

0.*

0.6.0
0.6.1

1.*

1.34
1.34.1

2.*

2.0.0
2.2.0
2.2.2
2.2.4
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.4.11
2.4.12
2.4.13
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.8.0
2.9.0
2.9.1
2.10.0
2.10.1
2.10.2
2.10.3
2.10.5
2.10.6

3.*

3.0.0
3.0.0.post1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.3.10
3.3.11
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.5.3

4.*

4.0.0b1
4.0.0b2
4.0.0b3
4.0.0rc1
4.0.0rc2
4.0.0
4.0.1
4.0.2
4.1.0rc1
4.1.0rc2
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.0rc1
4.2.0rc2
4.2.0rc3
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.4.0rc1
4.4.0rc2
4.4.0rc3
4.4.0rc4
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.6.0

5.*

5.0.0b1
5.0.0b2
5.0.0b3
5.0.0b4
5.0.0rc1
5.0.0rc2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.1.0a1
5.1.0b1
5.1.0b2
5.1.0b3
5.1.0b4
5.1.0b5
5.1.0b6
5.1.0b7
5.1.0
5.1.1
5.2.0
5.2.1
5.3.0b1
5.3.0b3
5.3.0b4
5.3.0b5
5.3.0
5.3.1

6.*

6.0.0b1
6.0.0b2
6.0.0
6.1.0
6.1.1