CVE-2024-31227
CVSS V2 None
CVSS V3 None
Description
Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem exists in Redis 7 prior to versions 7.2.6 and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Overview
- CVE ID
- CVE-2024-31227
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-07T19:51:04.520Z
- Last Modified Date
- 2024-10-07T20:20:56.702Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/redis/redis/security/advisories/GHSA-38p4-26x2-vqhh | x_refsource_CONFIRM |
https://github.com/redis/redis/commit/b351d5a3210e61cc3b22ba38a723d6da8f3c298a | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-31227 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31227 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-08 13:07:59 | Added to TrackCVE |