Redis is an in-memory database that persists on disk. Redis does not correctly identify keys accessed by `SORT_RO` and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. The problem exists in Redis 7.0 or newer and has been fixed in Redis 7.0.13 and 7.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade redisUpgrade redis-develUpgrade redis-doc | Dec 10, 2024 | Sep 6, 2023 |
| Alpine Linux | — | Upgrade redis | Aug 22, 2024 | Sep 6, 2023 |
| Debian | — | Upgrade redis | Feb 5, 2024 | Sep 6, 2023 |
| Freebsd | — | Upgrade redisUpgrade redis-develUpgrade redis70 | Sep 7, 2023 | Sep 7, 2023 |
| Gentoo Linux | — | Upgrade dev-db/redis. | Aug 8, 2024 | Sep 6, 2023 |
| Oracle_linux | — | Upgrade redis-docUpgrade redis-develUpgrade redis | Dec 7, 2024 | Sep 6, 2023 |
| Redhat_linux | — | Upgrade redis-docNo solution existsUpgrade redis-debuginfoUpgrade redis-debugsourceUpgrade redisUpgrade redis-devel | Feb 10, 2025 | Sep 6, 2023 |
| Redislabs Redis | — | Upgrade RedisLabs Redis to version 7.0.13Upgrade RedisLabs Redis to the latest version | Oct 17, 2025 | Sep 6, 2023 |
| Suse | — | Upgrade redis7 | Sep 21, 2023 | Sep 6, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 6, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub