Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9.
2023-03-01T16:15:09.400
2024-11-21T07:12:12.090
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redis | redis | < 6.0.18 | Yes |
Application | redis | redis | < 6.2.11 | Yes |
Application | redis | redis | < 7.0.9 | Yes |