CVE-2021-29478
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and earlier are not directly affected by this issue. The problem is fixed in version 6.2.3. An additional workaround to mitigate the problem without patching the `redis-server` executable is to prevent users from modifying the `set-max-intset-entries` configuration parameter. This can be done using ACL to restrict unprivileged users from using the `CONFIG SET` command.
EPSS 2.34% · 85.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redislabs | redis | 6.2.0 |
| fedoraproject | fedora | 33, 34 |
| redis | redis | >= 6.2.0, < 6.2.3 |
Exploit Intelligence
- https://redis.io/ (circl)
- https://github.com/redis/redis/security/advisories/GHSA-qh52-crrg-44g3 (circl)
- FEDORA-2021-3b267a756c (circl)
- FEDORA-2021-8b19c99d6a (circl)
- GLSA-202107-20 (circl)
- cve_db.json (github-poc)
- cve_db.json (github-poc)
- cve_db.json (github-poc)
- cve_db.json (github-poc)
- cve_db.json (github-poc)
…and 1 more exploits
Timeline
- May 3, 2021 CVE Published
- May 5, 2021 EPSS Score
- Jul 8, 2021 EPSS Score
- Nov 9, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 10, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 14, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 16, 2022 EPSS Score
- Jan 18, 2023 EPSS Score
References
- https://redis.io/ url
- https://github.com/redis/redis/security/advisories/GHSA-qh52-crrg-44g3 url
- FEDORA-2021-3b267a756c vendor-advisory
- FEDORA-2021-8b19c99d6a vendor-advisory
- GLSA-202107-20 vendor-advisory