vendor:
Redis
by:
Fakhri Zulkifli
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Redis
Affected Version From: 5.0
Affected Version To: 5.0
Patch Exists: YES
Related CWE: CVE-2018-12453
CPE: redis:5.0
Platforms Tested: Linux
2018
Redis 5.0 Denial of Service
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.
Mitigation:
Upgrade to Redis 5.0 or later versions