Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-31294


Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before 6.2 were not intended to have safety guarantees related to this.


Published

2023-07-15T23:15:09.203

Last Modified

2024-11-21T06:05:24.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redis redis < 6.2.0 Yes

References