Lucene search

K
cve[email protected]CVE-2015-4335
HistoryJun 09, 2015 - 2:59 p.m.

CVE-2015-4335

2015-06-0914:59:07
CWE-17
web.nvd.nist.gov
72
In Wild
cve
2015
4335
redis
remote code execution
eval command

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.7%

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

Affected configurations

NVD
Node
redislabsredisRange2.8.20
OR
redislabsredisMatch3.0.0
OR
redislabsredisMatch3.0.1
Node
debiandebian_linuxMatch8.0
OR
debiandebian_linuxMatch9.0

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.7%