The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade redis | Jul 30, 2024 | Oct 6, 2017 |
| Gentoo Linux | — | Upgrade dev-db/redis. | Aug 28, 2020 | Oct 6, 2017 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to the latest version | Aug 15, 2019 | Oct 6, 2017 |
| Suse | — | Upgrade redis | Jan 26, 2018 | Oct 6, 2017 |
| Ubuntu | — | Upgrade redis | Nov 19, 2024 | Oct 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub