Sploitus

CVE-2023-42809

No indexed exploits for CVE-2023-42809 yet

Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is running in. Version 3.22.0 contains a patch for this issue. Some post-fix advice is available. Do NOT use `Kryo5Codec` as deserialization codec, as it is still vulnerable to arbitrary object deserialization due to the `setRegistrationRequired(false)` call. On the contrary, `KryoCodec` is safe to use. The fix applied to `SerializationCodec` only consists of adding an optional allowlist of class names, even though making this behavior the default is recommended. When instantiating `SerializationCodec` please use the `SerializationCodec(ClassLoader classLoader, Set<String> allowedClasses)` constructor to restrict the allowed classes for deserialization.

Affected products
Java
Redisson
< 3.22.0
Fix
Available
CVSS 3.1
9.6 CRITICAL
EPSS
1.0% (61th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2023-10-04
CVE-2023-42809 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-42809 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-42809 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.