redis-parser 在 3.0.0 及之前版本中存在漏洞,该漏洞源于其在解析 RESP 协议时未对“多批量(multi-bulk)”长度值进行有效验证。攻击者可以通过提供一个声明长度过大的值,触发一个未被捕获的 RangeError 异常。当恶意或已被入侵的 Redis 服务端发送一个包含异常大长度值(大于 2^32 - 1)的精心构造的 RESP 头部时,可导致 Node.js 客户端进程崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NodeRedis | redis-parser | ≤ 3.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NodeRedis | redis-parser | 0 ~ 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet