QID 730590

Date Published: 2022-08-16

QID 730590: Redis Sandbox Escape Remote Code Execution (RCE) Vulnerability

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

QID Detection Logic (Unauthenticated) : This QID checks for vulnerable Redis instances by sending a crafted payload to read the /etc/passwd file.

Successful exploitation of the vulnerability may allow remote code execution and complete system compromise.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to update their Redis packages. For more information related to this vulnerability please refer to Debian Security Advisory
    Vendor References

    CVEs related to QID 730590

    Software Advisories
    Advisory ID Software Component Link
    dsa-5081 URL Logo www.debian.org/security/2022/dsa-5081