CVE Vulnerabilities

CVE-2015-4335

Published: Jun 09, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

Affected Software

NameVendorStart VersionEnd Version
RedisRedislabs*2.8.20 (including)
RedisRedislabs3.0.0 (including)3.0.0 (including)
RedisRedislabs3.0.1 (including)3.0.1 (including)
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatredis-0:2.8.21-1.el7ost*
RedisUbuntuartful*
RedisUbuntuesm-infra-legacy/trusty*
RedisUbuntuprecise*
RedisUbuntutrusty*
RedisUbuntutrusty/esm*
RedisUbuntuupstream*
RedisUbuntuutopic*
RedisUbuntuvivid*
RedisUbuntuwily*
RedisUbuntuyakkety*
RedisUbuntuzesty*

References