CVE-2024-51480

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Jan 8, 2025
CWE ID 190
CWE ID 122

Summary

CVE-2024-51480 is a vulnerability affecting RedisTimeSeries, a time-series database module for Redis. Authenticated users can trigger an integer overflow through the use of specific arguments in commands such as TS.QUERYINDEX, TS.MGET, TS.MRAGE, and TS.MREVRANGE. This integer overflow leads to a heap overflow, potentially allowing remote code execution. This issue has been resolved in versions 1.6.20, 1.8.15, 1.10.15, and 1.12.3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share