CVE Vulnerabilities

CVE-2015-4335

Published: Jun 09, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

Affected Software

Name Vendor Start Version End Version
Redis Redislabs * 2.8.20 (including)
Redis Redislabs 3.0.0 (including) 3.0.0 (including)
Redis Redislabs 3.0.1 (including) 3.0.1 (including)
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 RedHat redis-0:2.8.21-1.el7ost *
Redis Ubuntu artful *
Redis Ubuntu precise *
Redis Ubuntu trusty *
Redis Ubuntu upstream *
Redis Ubuntu utopic *
Redis Ubuntu vivid *
Redis Ubuntu wily *
Redis Ubuntu yakkety *
Redis Ubuntu zesty *

References