SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24834

A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution.

HIGH 8.8EPSS 41.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 41.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
41.41% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-122, CWE-680
Affected
redis/redis · fedoraproject/fedora
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.