VDB
CVE-2021-31294
CVE-2021-31294
PUBLISHED
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.
EPSS 1.31% · 68.4th percentile
Risk Scores
EPSS Score
1.31%
68.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | valkey | 0 |
| Bitnami | redis | 0, 0, 0 |
| Bitnami | keydb | 0 |
| Bitnami | valkey | 0, 0, 0 |
| Bitnami | redis | 0 |
| Bitnami | keydb | 0, 0, 0 |
Timeline
- Jul 15, 2023 CVE Published
- Jul 16, 2023 EPSS Score
- Aug 20, 2023 EPSS Score
- Sep 23, 2023 EPSS Score
- Oct 28, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 5, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Mar 14, 2024 EPSS Score
- Apr 17, 2024 EPSS Score
- May 22, 2024 EPSS Score
- Jun 25, 2024 EPSS Score
References
- https://github.com/redis/redis/commit/46f4ebbe842620f0976a36741a72482620aa4b48 url
- https://github.com/redis/redis/commit/6cbea7d29b5285692843bc1c351abba1a7ef326f url
- https://nvd.nist.gov/vuln/detail/CVE-2021-31294 url
- https://github.com/redis/redis/issues/8712 url
- https://security.netapp.com/advisory/ntap-20230814-0007/ url