Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-32626

Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This problem exists in all versions of Redis with Lua scripting support, starting from 2.6. The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14. For users unable to update an additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.5
References
Products affected by CVE-2021-32626
  • cpe:2.3:a:netapp:management_services_for_element_software:-
  • cpe:2.3:a:netapp:management_services_for_netapp_hci:-
  • cpe:2.3:a:oracle:communications_operations_monitor:4.3
  • cpe:2.3:a:oracle:communications_operations_monitor:4.4
  • cpe:2.3:a:oracle:communications_operations_monitor:5.0
  • Redis » Redis » Version: 2.6.0
    cpe:2.3:a:redis:redis:2.6.0
  • Redis » Redis » Version: 2.6.1
    cpe:2.3:a:redis:redis:2.6.1
  • Redis » Redis » Version: 2.6.10
    cpe:2.3:a:redis:redis:2.6.10
  • Redis » Redis » Version: 2.6.11
    cpe:2.3:a:redis:redis:2.6.11
  • Redis » Redis » Version: 2.6.12
    cpe:2.3:a:redis:redis:2.6.12
  • Redis » Redis » Version: 2.6.13
    cpe:2.3:a:redis:redis:2.6.13
  • Redis » Redis » Version: 2.6.14
    cpe:2.3:a:redis:redis:2.6.14
  • Redis » Redis » Version: 2.6.15
    cpe:2.3:a:redis:redis:2.6.15
  • Redis » Redis » Version: 2.6.16
    cpe:2.3:a:redis:redis:2.6.16
  • Redis » Redis » Version: 2.6.17
    cpe:2.3:a:redis:redis:2.6.17
  • Redis » Redis » Version: 2.6.2
    cpe:2.3:a:redis:redis:2.6.2
  • Redis » Redis » Version: 2.6.3
    cpe:2.3:a:redis:redis:2.6.3
  • Redis » Redis » Version: 2.6.4
    cpe:2.3:a:redis:redis:2.6.4
  • Redis » Redis » Version: 2.6.5
    cpe:2.3:a:redis:redis:2.6.5
  • Redis » Redis » Version: 2.6.6
    cpe:2.3:a:redis:redis:2.6.6
  • Redis » Redis » Version: 2.6.7
    cpe:2.3:a:redis:redis:2.6.7
  • Redis » Redis » Version: 2.6.8
    cpe:2.3:a:redis:redis:2.6.8
  • Redis » Redis » Version: 2.6.9
    cpe:2.3:a:redis:redis:2.6.9
  • Redis » Redis » Version: 2.8.0
    cpe:2.3:a:redis:redis:2.8.0
  • Redis » Redis » Version: 2.8.1
    cpe:2.3:a:redis:redis:2.8.1
  • Redis » Redis » Version: 2.8.10
    cpe:2.3:a:redis:redis:2.8.10
  • Redis » Redis » Version: 2.8.11
    cpe:2.3:a:redis:redis:2.8.11
  • Redis » Redis » Version: 2.8.12
    cpe:2.3:a:redis:redis:2.8.12
  • Redis » Redis » Version: 2.8.13
    cpe:2.3:a:redis:redis:2.8.13
  • Redis » Redis » Version: 2.8.14
    cpe:2.3:a:redis:redis:2.8.14
  • Redis » Redis » Version: 2.8.15
    cpe:2.3:a:redis:redis:2.8.15
  • Redis » Redis » Version: 2.8.16
    cpe:2.3:a:redis:redis:2.8.16
  • Redis » Redis » Version: 2.8.17
    cpe:2.3:a:redis:redis:2.8.17
  • Redis » Redis » Version: 2.8.18
    cpe:2.3:a:redis:redis:2.8.18
  • Redis » Redis » Version: 2.8.19
    cpe:2.3:a:redis:redis:2.8.19
  • Redis » Redis » Version: 2.8.2
    cpe:2.3:a:redis:redis:2.8.2
  • Redis » Redis » Version: 2.8.20
    cpe:2.3:a:redis:redis:2.8.20
  • Redis » Redis » Version: 2.8.21
    cpe:2.3:a:redis:redis:2.8.21
  • Redis » Redis » Version: 2.8.22
    cpe:2.3:a:redis:redis:2.8.22
  • Redis » Redis » Version: 2.8.23
    cpe:2.3:a:redis:redis:2.8.23
  • Redis » Redis » Version: 2.8.24
    cpe:2.3:a:redis:redis:2.8.24
  • Redis » Redis » Version: 2.8.3
    cpe:2.3:a:redis:redis:2.8.3
  • Redis » Redis » Version: 2.8.4
    cpe:2.3:a:redis:redis:2.8.4
  • Redis » Redis » Version: 2.8.5
    cpe:2.3:a:redis:redis:2.8.5
  • Redis » Redis » Version: 2.8.6
    cpe:2.3:a:redis:redis:2.8.6
  • Redis » Redis » Version: 2.8.7
    cpe:2.3:a:redis:redis:2.8.7
  • Redis » Redis » Version: 2.8.8
    cpe:2.3:a:redis:redis:2.8.8
  • Redis » Redis » Version: 2.8.9
    cpe:2.3:a:redis:redis:2.8.9
  • Redis » Redis » Version: 3.0.0
    cpe:2.3:a:redis:redis:3.0.0
  • Redis » Redis » Version: 3.0.1
    cpe:2.3:a:redis:redis:3.0.1
  • Redis » Redis » Version: 3.0.2
    cpe:2.3:a:redis:redis:3.0.2
  • Redis » Redis » Version: 3.0.3
    cpe:2.3:a:redis:redis:3.0.3
  • Redis » Redis » Version: 3.0.4
    cpe:2.3:a:redis:redis:3.0.4
  • Redis » Redis » Version: 3.0.5
    cpe:2.3:a:redis:redis:3.0.5
  • Redis » Redis » Version: 3.0.6
    cpe:2.3:a:redis:redis:3.0.6
  • Redis » Redis » Version: 3.0.7
    cpe:2.3:a:redis:redis:3.0.7
  • Redis » Redis » Version: 3.2.0
    cpe:2.3:a:redis:redis:3.2.0
  • Redis » Redis » Version: 3.2.1
    cpe:2.3:a:redis:redis:3.2.1
  • Redis » Redis » Version: 3.2.10
    cpe:2.3:a:redis:redis:3.2.10
  • Redis » Redis » Version: 3.2.11
    cpe:2.3:a:redis:redis:3.2.11
  • Redis » Redis » Version: 3.2.12
    cpe:2.3:a:redis:redis:3.2.12
  • Redis » Redis » Version: 3.2.13
    cpe:2.3:a:redis:redis:3.2.13
  • Redis » Redis » Version: 3.2.2
    cpe:2.3:a:redis:redis:3.2.2
  • Redis » Redis » Version: 3.2.3
    cpe:2.3:a:redis:redis:3.2.3
  • Redis » Redis » Version: 3.2.4
    cpe:2.3:a:redis:redis:3.2.4
  • Redis » Redis » Version: 3.2.5
    cpe:2.3:a:redis:redis:3.2.5
  • Redis » Redis » Version: 3.2.6
    cpe:2.3:a:redis:redis:3.2.6
  • Redis » Redis » Version: 3.2.7
    cpe:2.3:a:redis:redis:3.2.7
  • Redis » Redis » Version: 3.2.8
    cpe:2.3:a:redis:redis:3.2.8
  • Redis » Redis » Version: 3.2.9
    cpe:2.3:a:redis:redis:3.2.9
  • Redis » Redis » Version: 4.0.0
    cpe:2.3:a:redis:redis:4.0.0
  • Redis » Redis » Version: 4.0.1
    cpe:2.3:a:redis:redis:4.0.1
  • Redis » Redis » Version: 4.0.10
    cpe:2.3:a:redis:redis:4.0.10
  • Redis » Redis » Version: 4.0.11
    cpe:2.3:a:redis:redis:4.0.11
  • Redis » Redis » Version: 4.0.12
    cpe:2.3:a:redis:redis:4.0.12
  • Redis » Redis » Version: 4.0.13
    cpe:2.3:a:redis:redis:4.0.13
  • Redis » Redis » Version: 4.0.14
    cpe:2.3:a:redis:redis:4.0.14
  • Redis » Redis » Version: 4.0.2
    cpe:2.3:a:redis:redis:4.0.2
  • Redis » Redis » Version: 4.0.3
    cpe:2.3:a:redis:redis:4.0.3
  • Redis » Redis » Version: 4.0.4
    cpe:2.3:a:redis:redis:4.0.4
  • Redis » Redis » Version: 4.0.5
    cpe:2.3:a:redis:redis:4.0.5
  • Redis » Redis » Version: 4.0.6
    cpe:2.3:a:redis:redis:4.0.6
  • Redis » Redis » Version: 4.0.7
    cpe:2.3:a:redis:redis:4.0.7
  • Redis » Redis » Version: 4.0.8
    cpe:2.3:a:redis:redis:4.0.8
  • Redis » Redis » Version: 4.0.9
    cpe:2.3:a:redis:redis:4.0.9
  • Redis » Redis » Version: 5.0.0
    cpe:2.3:a:redis:redis:5.0.0
  • Redis » Redis » Version: 5.0.1
    cpe:2.3:a:redis:redis:5.0.1
  • Redis » Redis » Version: 5.0.10
    cpe:2.3:a:redis:redis:5.0.10
  • Redis » Redis » Version: 5.0.11
    cpe:2.3:a:redis:redis:5.0.11
  • Redis » Redis » Version: 5.0.12
    cpe:2.3:a:redis:redis:5.0.12
  • Redis » Redis » Version: 5.0.13
    cpe:2.3:a:redis:redis:5.0.13
  • Redis » Redis » Version: 5.0.2
    cpe:2.3:a:redis:redis:5.0.2
  • Redis » Redis » Version: 5.0.3
    cpe:2.3:a:redis:redis:5.0.3
  • Redis » Redis » Version: 5.0.4
    cpe:2.3:a:redis:redis:5.0.4
  • Redis » Redis » Version: 5.0.5
    cpe:2.3:a:redis:redis:5.0.5
  • Redis » Redis » Version: 5.0.6
    cpe:2.3:a:redis:redis:5.0.6
  • Redis » Redis » Version: 5.0.7
    cpe:2.3:a:redis:redis:5.0.7
  • Redis » Redis » Version: 5.0.8
    cpe:2.3:a:redis:redis:5.0.8
  • Redis » Redis » Version: 5.0.9
    cpe:2.3:a:redis:redis:5.0.9
  • Redis » Redis » Version: 6.0.0
    cpe:2.3:a:redis:redis:6.0.0
  • Redis » Redis » Version: 6.0.1
    cpe:2.3:a:redis:redis:6.0.1
  • Redis » Redis » Version: 6.0.10
    cpe:2.3:a:redis:redis:6.0.10
  • Redis » Redis » Version: 6.0.11
    cpe:2.3:a:redis:redis:6.0.11
  • Redis » Redis » Version: 6.0.12
    cpe:2.3:a:redis:redis:6.0.12
  • Redis » Redis » Version: 6.0.13
    cpe:2.3:a:redis:redis:6.0.13
  • Redis » Redis » Version: 6.0.14
    cpe:2.3:a:redis:redis:6.0.14
  • Redis » Redis » Version: 6.0.15
    cpe:2.3:a:redis:redis:6.0.15
  • Redis » Redis » Version: 6.0.2
    cpe:2.3:a:redis:redis:6.0.2
  • Redis » Redis » Version: 6.0.3
    cpe:2.3:a:redis:redis:6.0.3
  • Redis » Redis » Version: 6.0.4
    cpe:2.3:a:redis:redis:6.0.4
  • Redis » Redis » Version: 6.0.5
    cpe:2.3:a:redis:redis:6.0.5
  • Redis » Redis » Version: 6.0.6
    cpe:2.3:a:redis:redis:6.0.6
  • Redis » Redis » Version: 6.0.7
    cpe:2.3:a:redis:redis:6.0.7
  • Redis » Redis » Version: 6.0.8
    cpe:2.3:a:redis:redis:6.0.8
  • Redis » Redis » Version: 6.0.9
    cpe:2.3:a:redis:redis:6.0.9
  • Redis » Redis » Version: 6.2.0
    cpe:2.3:a:redis:redis:6.2.0
  • Redis » Redis » Version: 6.2.1
    cpe:2.3:a:redis:redis:6.2.1
  • Redis » Redis » Version: 6.2.2
    cpe:2.3:a:redis:redis:6.2.2
  • Redis » Redis » Version: 6.2.3
    cpe:2.3:a:redis:redis:6.2.3
  • Redis » Redis » Version: 6.2.4
    cpe:2.3:a:redis:redis:6.2.4
  • Redis » Redis » Version: 6.2.5
    cpe:2.3:a:redis:redis:6.2.5
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Fedoraproject » Fedora » Version: 33
    cpe:2.3:o:fedoraproject:fedora:33
  • Fedoraproject » Fedora » Version: 34
    cpe:2.3:o:fedoraproject:fedora:34
  • Fedoraproject » Fedora » Version: 35
    cpe:2.3:o:fedoraproject:fedora:35


Contact Us

Shodan ® - All rights reserved