Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade redis | Aug 30, 2017 | Jun 9, 2015 |
| Debian | — | Upgrade redis | Jul 30, 2024 | Jun 9, 2015 |
| Freebsd | — | Upgrade redisUpgrade redis-devel | Dec 10, 2025 | Jun 8, 2015 |
| Gentoo Linux | — | Upgrade dev-db/redis. | Oct 30, 2017 | Jun 9, 2015 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to the latest version | Aug 15, 2019 | Jun 9, 2015 |
| Suse | — | Upgrade redis-debugsourceUpgrade redis-debuginfoUpgrade redis | Dec 18, 2015 | Jun 9, 2015 |
| Ubuntu | — | Upgrade redis | Nov 19, 2024 | Jun 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub