Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreRedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs.
An application that passes user-controlled values to findByMetadata() on a tag-typed metadata field allows an attacker to inject RediSearch syntax (e.g. x} | *) that breaks out of the tag clause and matches all indexed chat messages across every conversation in the index.
Spring AI:
| Fix version | Availability |
|---|---|
| 2.0.1 | OSS |
| 2.0.0.1 | Enterprise Support Only |
No further mitigation steps are necessary.
This issue was discovered internally and later reported independently by Tran Hoang Phuc Quan - https://github.com/PhucQuan ([email protected]) from Viettel Networks
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy