SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32672

Redis is an open source, in-memory database that persists on disk.

MEDIUM 4.3EPSS 1.83%

Does this matter?

Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.

Description

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.83% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
redis/redis · redhat/software collections · redhat/enterprise linux · debian/debian linux · fedoraproject/fedora · netapp/management services for element software · netapp/management services for netapp hci · oracle/communications operations monitor
Source
security-advisories@github.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.