Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-31227

Published: October 8, 2024Last modified: October 8, 2024

Description

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Severity score breakdown

ParameterValue
Base score4.4
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSredisFixed (7.0.15-r1)
StreamredisFixed (7.2.5-r1)

References

ON THIS PAGE