Redis
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*
- >= 7.0.0
A denial-of-service vulnerability has been identified in Redis versions 7.0.0 and later. The issue arises when an authenticated user with sufficient privileges creates a malformed Access Control List (ACL) selector. When this malformed selector is accessed, it triggers a server panic, leading to a crash and subsequent denial-of-service condition.
Exploitation of this vulnerability causes a server panic, leading to a crash and a denial-of-service condition.
Users can upgrade to Redis versions 7.2.7 or 7.4.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.