Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-51741

Опубликовано: 06 янв. 2025
Источник: debian
EPSS Низкий

Описание

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
redisfixed5:7.0.15-3package
redisnot-affectedbullseyepackage
redictfixed7.3.2+ds-1package
valkeyfixed8.0.2+dfsg1-1package

Примечания

  • https://github.com/redis/redis/security/advisories/GHSA-prpq-rh5h-46g9

  • Introduced by: https://github.com/redis/redis/commit/55c81f2cd3da82f9f570000875e006b9046ddef3 (7.0-rc1)

  • Fixed by: https://github.com/redis/redis/commit/15e212bf69de28d2b4585aa79cc2a40f49e4a94d (7.2.7)

  • https://codeberg.org/redict/redict/issues/60

  • Fixed by: https://codeberg.org/redict/redict/commit/ba5dcb3b161e357de95ec7aa4ab03688559e7222

  • Fixed by: https://github.com/valkey-io/valkey/commit/7977c55ac9bea7d1443c32ef5ec020767c086d3a

EPSS

Процентиль: 14%
0.00045
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
redhat
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
nvd
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS3: 4.4
msrc
10 месяцев назад

Redis allows denial-of-service due to malformed ACL selectors

CVSS3: 4.4
fstec
около 1 года назад

Уязвимость системы управления базами данных Redis, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00045
Низкий