CVE-2017-1000248: Critical severity redis vulnerability
Published Nov 17, 2017
·Updated
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
Other sources
Redis-store prior to 1.4.0 allows unsafe objects to be loaded from redis
Affected Software
2 affected componentsFixes available
rubygems/redis-store<1.4.0
1.4.0
Redis-store Redis-store<=1.3.0
Remediation
Event History
Nov 17, 2017
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Dec 6, 2017
Advisory Published
04:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000248?
CVE-2017-1000248 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-1000248?
To mitigate CVE-2017-1000248, upgrade redis-store to version 1.4.0 or later.
3
What types of software are affected by CVE-2017-1000248?
CVE-2017-1000248 affects redis-store versions prior to 1.4.0.
4
What is the impact of CVE-2017-1000248?
The impact of CVE-2017-1000248 is that unsafe objects can be loaded from Redis, potentially leading to unauthorized access.
5
Is CVE-2017-1000248 related to any other vulnerabilities?
CVE-2017-1000248 is primarily a standalone issue but is part of the broader category of vulnerabilities concerning serialization and object loading.