CVE-2023-45145
LowAdvisory
Published 18 Oct 2023In the index since 6 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.6
- base score, highest
- EPSS
- 0.004
- 37th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 12
- of 17,781 indexed, latest versions
- Container images
- 12
- deployed by those charts
- Fix available
- 4 of 4
- affected packages
Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.
Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| redisbitnami | 6.0.8-0, 6.0.12-0, 6.2.7-150, 7.0.8-0+4 more | 6.2.14 | 8 |
| redisapk | 6.2.7-r0, 7.0.4-r0 | 6.2.14-r0, 7.0.14-r0 | 2 |
| redisdeb | 5:5.0.7-2ubuntu0.1 | 5:5.0.7-2ubuntu0.1+esm2 | 2 |
| Redis (TM)bitnami | 7.2.1 | 6.2.14 | 1 |
- OSV records
- ALPINE-CVE-2023-45145BIT-redis-2023-45145UBUNTU-CVE-2023-45145
- Also known as
- BIT-keydb-2023-45145, BIT-valkey-2023-45145, GHSA-ghmp-889m-7cvx, USN-6531-1
Charts affected
12 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| difydify-helmVerified publisher | 0.38.0 | 1 of 11See more | 22,002 |
| chatwootchatwootVerified publisher | 2.0.24 | 1 of 3See more | 9,203 |
| netris-controllernetrisai | 2.8.2 | 1 of 14See more | 30,326 |
| thingsboard-clusterthingsboard-cluster-bettaVerified publisher | 0.2.26 | 1 of 6See more | 14,566 |
| appwriteappwrite-helmVerified publisher | 1.3.2 | 1 of 8See more | 9,847 |
| supportpalevilgn0me | 0.1.6 | 1 of 1See more | 20,933 |
| redisredisVerified publisher | 0.1.1 | 1 of 1See more | 1,594 |
| redisredis-arm | 17.8.0 | 1 of 1See more | 1,906 |
| reload-counterreload-counter | 0.1.0 | 1 of 1See more | 1,009 |
| redis-high-availabilitysomeblackmagic | 1.3.10 | 1 of 3See more | 3,148 |
| testing-multitoolsomeblackmagic | 0.1.2 | 1 of 1See more | 30,687 |
| webapp-chartwebappchart | 1.0.0 | 1 of 1See more | 1,201 |
Container images carrying it
12 by charts deploying them
A fixed version is listed for 4 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| alaaamin/ | 46da5844794e | redis | 6.2.14-r0 | 1 |
| amagdi888/ | d8a10fc8faf6 | redis | 7.0.14-r0 | 1 |
| bitnamilegacy/ | 1161dcd293a0 | redis | 6.2.14 | 1 |
| bitnamilegacy/ | 59293f5206b7 | redis | 6.2.14 | 1 |
| bitnamilegacy/ | 7788b908dd0d | redis | 6.2.14 | 1 |
| bitnamilegacy/ | bf01d031ba8c | redis | 6.2.14 | 1 |
| bitnamilegacy/ | fa288394f402 | redis Redis (TM) | 6.2.14 6.2.14 | 1 |
| netrisai/ | a4c0140d1696 | redis | 6.2.14 | 1 |
| someblackmagic/ | 6eca64b6b440 | redis | 5:5.0.7-2ubuntu0.1+esm2 | 1 |
| ghcr.io/ | 118a403046f7 | redis | 6.2.14 | 1 |
| mcr.microsoft.com/ | e1e9cf5297a6 | redis | 6.2.14 | 1 |
| public.ecr.aws/ | 573779e57fae | redis | 5:5.0.7-2ubuntu0.1+esm2 | 1 |