Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whxg-wx83-85p5

Опубликовано: 06 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Lua library commands may lead to stack overflow and potential RCE

Impact

An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution.

The problem exists in all versions of Redis with Lua scripting.

Patches

The problem is fixed in Redis 6.2.16, 7.2.6, 7.4.1.

Credit

The problem was reported by ankki-zsyang, Shenzhen Ankki Technologies Co.Ltd.

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.16

6.2.16

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.2.0, <7.2.6

7.2.6

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.4.0, <7.4.1

7.4.1

EPSS

Процентиль: 91%
0.04495
Низкий

7 High

CVSS3

Дефекты

CWE-20
CWE-121

Связанные уязвимости

CVSS3: 7
ubuntu
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
redhat
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
nvd
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
msrc
больше 1 года назад

Lua library commands may lead to stack overflow and RCE in Redis

CVSS3: 7
debian
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An ...

EPSS

Процентиль: 91%
0.04495
Низкий

7 High

CVSS3

Дефекты

CWE-20
CWE-121