Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-53330
HistoryJul 22, 2021 - 12:00 a.m.

Redis remote code execution vulnerability

2021-07-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
redis
vulnerability
remote code execution
32-bit systems
*bit* command
proto-max-bulk-len

EPSS

0.017

Percentile

87.9%

Redis is an open source ANSI C, network-enabled, memory-based, and persistent logging, Key-Value storage database with a multilingual API. The vulnerability can be exploited to attack 32-bit Redis programs running on 32-bit systems by combining the BIT command with the proto-max-bulk-len configuration parameter, which can cause a shaping overflow and eventually lead to remote code execution.