You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Feb 9, 2019. It is now read-only.
The current version of sedis has a critical bug - it doesn't release broken objects back to the jedis pool correctly. This has the side effect of new calls returning results of previous calls; essentially you get "random" output. This is very bad.
Any chance you can either fork sedis and incorporate that PR, or just get rid of the dependency on sedis? This bug has very bad implications for anything that uses RedisCacheApi, especially things surrounding security/authentication, such as SecureSocial or other plugins.
Here's a more detailed issue with the incorrect jedis pool usage: redis/jedis#909
It also details how to reproduce getting incorrect output from redis: (redis/jedis#909 (comment))