CVE-2025-25069

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 7, 2025
Updated: Feb 13, 2025
CWE ID 115

Summary

CVE-2025-25069 is a Cross-Protocol Scripting vulnerability affecting Apache Kvrocks. This issue allows a maliciously crafted request to be treated as a valid RESP response, triggering dangerous database operations. Kvrocks fails to detect "Host:" or "POST" in RESP requests, making it possible for attackers to exploit this vulnerability and chain it with Server Side Request Forgery (SSRF). This issue is reminiscent of CVE-2016-10517 in Redis. Affecting all versions of Apache Kvrocks, from the initial release to 2.11.0, users are strongly advised to upgrade to version 2.11.1 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share