networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://www.reddit.com/r/redis/comments/5r8wxn/redis_327_is_out_important_security_fixes_inside/ | third party advisory issue tracking |
https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTES | third party advisory issue tracking |
http://www.securityfocus.com/bid/101572 | third party advisory vdb entry |
https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50 | third party advisory issue tracking |