Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4335

Опубликовано: 04 июн. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

A flaw was discovered in redis that could allow an authenticated user, who was able to use the EVAL command to run Lua code, to break out of the Lua sandbox and execute arbitrary code on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)redisAffected
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7redisFixedRHSA-2015:167624.08.2015

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1228327redis: Lua sandbox escape and arbitrary code execution

EPSS

Процентиль: 95%
0.09636
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

nvd
около 11 лет назад

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

debian
около 11 лет назад

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to ex ...

github
больше 4 лет назад

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

fstec
около 11 лет назад

Уязвимость системы управления базами данных Redis, позволяющая нарушителю выполнить произвольный Lua-байт-код

EPSS

Процентиль: 95%
0.09636
Низкий

6.8 Medium

CVSS2