Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37254
HistorySep 24, 2022 - 6:58 a.m.

Remote Code Execution (RCE)

2022-09-2406:58:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
redis
rce
vulnerability
integer overflow
xautoclaim
command
malicious code

0.029 Low

EPSS

Percentile

90.8%

Redis is vulnerable to remote code execution. The vulnerability exists due to an integer overflow when executing an XAUTOCLAIM command on a stream key in a specific state, with a specially crafted COUNT argument allowing an attacker to inject maliciously crafted code into the system.