FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

py39-redis -- can send response data to the client of an unrelated request

Affected packages
py39-redis < 4.3.6
4.4.0 <= py39-redis < 4.4.3
4.5.0 <= py39-redis < 4.5.3

Details

VuXML ID 3f6d6181-79b2-4d33-bb1e-5d3f9df0c1d1
Discovery 2023-03-26
Entry 2023-04-09

drago-balto reports:

redis-py before 4.5.3, as used in ChatGPT and other products, leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a pipeline operation), and can send response data to the client of an unrelated request in an off-by-one manner.

The fixed versions for this CVE Record are 4.3.6, 4.4.3, and 4.5.3, but [are believed to be incomplete](https://github.com/redis/redis-py/issues/2665).

CVE-2023-28859 has been assigned the issues caused by the incomplete fixes.

References

CVE Name CVE-2023-28858
URL https://osv.dev/vulnerability/GHSA-24wv-mv5m-xv4h