mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 03:02:30 +00:00
753 B
753 B
CVE-2013-7458
Description
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
POC
Reference
- https://github.com/antirez/linenoise/issues/121
- https://github.com/antirez/redis/blob/3.2/00-RELEASENOTES
- https://github.com/antirez/redis/pull/3322