CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
75.8%
redis is vulnerable to Remote Code Execution (RCE). This vulnerability occurs due to a flaw in the way that Redis handles key names. An attacker can exploit this vulnerability to cause Redis to crash or to execute arbitrary code.
github.com/redis/redis/releases/tag/7.0.12
github.com/redis/redis/security/advisories/GHSA-4cfx-h9gq-xpx3
lists.fedoraproject.org/archives/list/[email protected]/message/MIF5MAGYARYUMRFK7PQI7HYXMK2HZE5T/
lists.fedoraproject.org/archives/list/[email protected]/message/TDNNH2ONMVNBQ6LUIAOAGDNFPKXNST5K/
security-tracker.debian.org/tracker/CVE-2023-36824
security.netapp.com/advisory/ntap-20230814-0009/