linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
{
"binaries": [
{
"binary_name": "redis-sentinel",
"binary_version": "2:3.0.6-1ubuntu0.2"
},
{
"binary_name": "redis-server",
"binary_version": "2:3.0.6-1ubuntu0.2"
},
{
"binary_name": "redis-tools",
"binary_version": "2:3.0.6-1ubuntu0.2"
}
],
"availability": "No subscription required"
}