Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-51741

Опубликовано: 06 янв. 2025
Источник: debian
EPSS Низкий

Описание

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
redisfixed5:7.0.15-3package
redisnot-affectedbullseyepackage
redictfixed7.3.2+ds-1package
valkeyfixed8.0.2+dfsg1-1package

Примечания

  • https://github.com/redis/redis/security/advisories/GHSA-prpq-rh5h-46g9

  • Introduced by: https://github.com/redis/redis/commit/55c81f2cd3da82f9f570000875e006b9046ddef3 (7.0-rc1)

  • Fixed by: https://github.com/redis/redis/commit/15e212bf69de28d2b4585aa79cc2a40f49e4a94d (7.2.7)

  • https://codeberg.org/redict/redict/issues/60

  • Fixed by: https://codeberg.org/redict/redict/commit/ba5dcb3b161e357de95ec7aa4ab03688559e7222

  • Fixed by: https://github.com/valkey-io/valkey/commit/7977c55ac9bea7d1443c32ef5ec020767c086d3a

EPSS

Процентиль: 21%
0.00067
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
6 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
redhat
6 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
nvd
6 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 4.4
fstec
8 месяцев назад

Уязвимость системы управления базами данных Redis, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00067
Низкий