V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-31228
ANC
Medium

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially c…

CVSS
5.5
Medium
EPSS
0.01
p58
Published
2024-01-01
Updated
2024-01-01
Description

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COMMAND LIST` and ACL definitions. Matching of extremely long patterns may result in unbounded recursion, leading to stack overflow and process crash. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Tags · CWE
CWE-674
CAPEC-230
CAPEC-231
Affected products
Redis 2.2.5–6.2.16Redis 7.2.0–7.2.6Redis
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.010 · p58
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
Tracked
Tracked
redictTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redisTracked
redis-cliTracked
redis-develTracked
valkeyTracked
redis*Tracked
Source databases
ANC
DEB
CVE
RED
UBU