Description

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.

INFO

Published Date :

2025-02-07T12:46:11.350Z

Last Modified :

2025-02-13T21:21:42.342Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-25069 vulnerability.

Vendors Products
Apache
  • Kvrocks
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-25069.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact