FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-18 11:12:36 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
3f6d6181-79b2-4d33-bb1e-5d3f9df0c1d1py39-redis -- can send response data to the client of an unrelated request

drago-balto reports:

redis-py before 4.5.3, as used in ChatGPT and other products, leaves a connection open after canceling an async Redis command at an inopportune time (in the case of a pipeline operation), and can send response data to the client of an unrelated request in an off-by-one manner.

The fixed versions for this CVE Record are 4.3.6, 4.4.3, and 4.5.3, but [are believed to be incomplete](https://github.com/redis/redis-py/issues/2665).

CVE-2023-28859 has been assigned the issues caused by the incomplete fixes.


Discovery 2023-03-26
Entry 2023-04-09
py39-redis
< 4.3.6

ge 4.4.0 lt 4.4.3

ge 4.5.0 lt 4.5.3

CVE-2023-28858
https://osv.dev/vulnerability/GHSA-24wv-mv5m-xv4h