Cross-Protocol Scripting Vulnerability in Apache Kvrocks
CVE-2025-25069
6.5MEDIUM
What is CVE-2025-25069?
A Cross-Protocol Scripting vulnerability exists in Apache Kvrocks due to inadequate validation of HTTP requests within RESP protocol handling. This flaw allows malicious actors to send crafted HTTP requests that Kvrocks incorrectly interprets as valid RESP commands. The vulnerability could lead to dangerous database operations, especially when exploited in conjunction with Server-Side Request Forgery (SSRF) attacks. Users are advised to upgrade to Kvrocks version 2.11.1 to mitigate this issue.
Affected Version(s)
Apache Kvrocks 0 <= 2.11.0