Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-31294
HistoryJul 15, 2023 - 12:00 a.m.

CVE-2021-31294

2023-07-1500:00:00
ubuntu.com
ubuntu.com
7
redis
security
vulnerability

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

25.2%

Redis before 6cbea7d allows a replica to cause an assertion failure in a
primary server by sending a non-administrative command (specifically, a SET
command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions
before 6.2 were not intended to have safety guarantees related to this.

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

25.2%