[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2REDIS6-2023-003 --- redis

ID: oval:org.secpod.oval:def:1701651Date: (C)2023-10-26   (M)2023-11-13
Class: PATCHFamily: unix




A flaw was found in the Redis database where Lua scripts can be manipulated to overcome ACL rules. This flaw allows an attacker with access to Redis to inject Lua code that executes the potentially higher privileges of another Redis user. A flaw was found in the Redis database when a malformed Lua script can cause a NULL pointer dereference. This flaw allows an attacker to load a crafting script, which results in a crash of the redis-server process

Platform:
Amazon Linux 2
Product:
redis
Reference:
ALAS2REDIS6-2023-003
CVE-2022-24735
CVE-2022-24736
CVE    2
CVE-2022-24736
CVE-2022-24735
CPE    2
cpe:/a:redis:redis
cpe:/o:amazon:linux:2

© SecPod Technologies