# sonatype-2023-1621

## redis-py - Race Condition [ CVE-2023-28858 ]

**Published:** Mar 24, 2023

**CVSS Score:** Medium 6.8

### Security Details

**CVE ID:** sonatype-2023-1621  
**CVE Description:** redis-py - Race Condition [ CVE-2023-28858 ]  
**Published:** Mar 24, 2023  
**CVSS Score & Severity:** 6.8 Medium  
**CVSS Vector:** CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H  
**EPSS Score:** 0%

**Malware:** malware

**KEV Status:** Not in KEV Catalog: No known exploits

### Affected Ecosystems

**Source:** Sonatype

### References

- [GitHub · Advisory · GHSA-24wv-mv5m-xv4h](https://github.com/advisories/GHSA-24wv-mv5m-xv4h)  
- [GitHub · PR #2641](https://github.com/redis/redis-py/pull/2641)  
- [openai.com](https://openai.com/blog/march-20-chatgpt-outage)  
- [bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/openai-chatgpt-payment-data-leak-caused-by-open-source-bug/)
