CVE-2016-10517

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
24/10/2017
Last modified:
20/04/2025

Description

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:* 3.2.7 (excluding)