The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-redis | Jul 30, 2024 | Oct 6, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-db-redis | Aug 28, 2020 | Oct 6, 2017 | |
| Redislabs Redis | redislabs-redis-upgrade-latest | Aug 15, 2019 | Oct 6, 2017 | |
| Suse | — | suse-upgrade-redis | Jan 26, 2018 | Oct 6, 2017 |
| Ubuntu | ubuntu-upgrade-redis | Nov 19, 2024 | Oct 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub