CVE-2024-31449
CVSS 3.1 Score 7 of 10 (high)
Details
Summary
CVE-2024-31449 is a newly disclosed vulnerability affecting Redis, an open-source in-memory database. An authenticated user can take advantage of a stack buffer overflow in the bit library, which is part of Redis' Lua scripting engine. Successful exploitation of this issue may result in remote code execution. This vulnerability exists in all versions of Redis with Lua scripting. Redis users are strongly advised to upgrade to versions 6.2.16, 7.2.6, or 7.4.1, as these releases contain the necessary patch. At this time, there are no documented workarounds for CVE-2024-31449.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Redis
Affected Vendors
- Redis