{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Out of bounds write due to improper code logic after a valid authentication",
    "tracking": {
      "current_release_date": "2026-08-11T17:08:21+00:00",
      "generator": {
        "date": "2026-08-11T17:08:21+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2023-47004",
      "initial_release_date": "2023-11-07T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T17:08:21+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.7.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.7.0",
              "product_id": "rhacm-2",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhacm2/redisgraph-tls-rhel8",
            "product": {
              "name": "rhacm2/redisgraph-tls-rhel8",
              "product_id": "rhacm2/redisgraph-tls-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/redisgraph-tls-rhel8?repository_url=registry.redhat.io/rhacm2/redisgraph-tls-rhel8"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/redisgraph-tls-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.7.0",
          "product_id": "rhacm-2:rhacm2/redisgraph-tls-rhel8"
        },
        "product_reference": "rhacm2/redisgraph-tls-rhel8",
        "relates_to_product_reference": "rhacm-2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-47004",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "discovery_date": "2023-11-07T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhacm-2:rhacm2/redisgraph-tls-rhel8"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "The default security model [1] for Redis servers dictates that deployments should be made in trusted environments and accessed by trusted clients. Therefore, using the default model, an attacker should only be able to trigger this vulnerability through adjacent networks after compromise of internal access controls.\n\n[1] https://redis.io/docs/management/security/",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "An out-of-bounds write flaw was found in RedisGraph, a module for the Redis server, due to improper code logic after a valid authentication. This issue may lead to arbitrary code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhacm-2:rhacm2/redisgraph-tls-rhel8"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-47004"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47004"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-47004"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "rhacm-2:rhacm2/redisgraph-tls-rhel8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "rhacm-2:rhacm2/redisgraph-tls-rhel8"
          ]
        }
      ],
      "title": "Out of bounds write due to improper code logic after a valid authentication"
    }
  ]
}