Skip to content
This repository was archived by the owner on Feb 9, 2019. It is now read-only.
This repository was archived by the owner on Feb 9, 2019. It is now read-only.

Redis plugin - Sedis pool bug #179

@dontgitit

Description

@dontgitit

Hi,

The current version of sedis has a critical bug - it doesn't release broken objects back to the jedis pool correctly. This has the side effect of new calls returning results of previous calls; essentially you get "random" output. This is very bad.

There's a PR with a fix: pk11/sedis#14

Any chance you can either fork sedis and incorporate that PR, or just get rid of the dependency on sedis? This bug has very bad implications for anything that uses RedisCacheApi, especially things surrounding security/authentication, such as SecureSocial or other plugins.

Here's a more detailed issue with the incorrect jedis pool usage: redis/jedis#909
It also details how to reproduce getting incorrect output from redis: (redis/jedis#909 (comment))

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions