CVE-2023-47003: Null Pointer Dereference
Published Nov 16, 2023
·Updated
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlockItemIsDeleted.
Affected Software
1 affected component
Redislabs Redisgraph=2.12.10
Event History
Nov 16, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in RedisGraph?
The vulnerability ID for this issue in RedisGraph is CVE-2023-47003.
2
What is the severity level of CVE-2023-47003?
The severity level of CVE-2023-47003 is critical.
3
How can an attacker exploit CVE-2023-47003?
An attacker can exploit CVE-2023-47003 by executing arbitrary code and causing a denial of service via a crafted string in DataBlock_ItemIsDeleted.
4
Which version of RedisGraph is affected by CVE-2023-47003?
RedisGraph version 2.12.10 is affected by CVE-2023-47003.
5
Is there a fix available for CVE-2023-47003?
Yes, please refer to the reference link for more information on how to fix CVE-2023-47003.