VDB
CVE-2021-31294
CVE-2021-31294
PUBLISHED
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
EPSS 0.23% · 46.7th percentile
Risk Scores
EPSS Score
0.23%
46.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | valkey | 0 |
| Bitnami | redis | 0, 0, 0 |
| Bitnami | keydb | 0 |
| Bitnami | valkey | 0, 0, 0 |
| Bitnami | redis | 0 |
| Bitnami | keydb | 0, 0, 0 |
Exploit Intelligence
Timeline
- Jul 15, 2023 CVE Published
- Jul 16, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Sep 23, 2023 EPSS Score
- Oct 27, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 4, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Mar 13, 2024 EPSS Score
- Apr 17, 2024 EPSS Score
- May 21, 2024 EPSS Score
- Jun 24, 2024 EPSS Score
References
- https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48 url
- https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f url
- https://github.com/redis/redis/issues/8712 url
- https://security.netapp.com/advisory/ntap-20230814-0007/ url
- https://nvd.nist.gov/vuln/detail/CVE-2021-31294 url