CVE-2020-35668

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
23/12/2020
Last modified:
28/12/2020

Description

RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redislabs:redisgraph:*:*:*:*:*:*:*:* 2.0.0 (including) 2.2.11 (excluding)