Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Redis | Redislabs | * | 2.8.20 (including) |
| Redis | Redislabs | 3.0.0 (including) | 3.0.0 (including) |
| Redis | Redislabs | 3.0.1 (including) | 3.0.1 (including) |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | redis-0:2.8.21-1.el7ost | * |
| Redis | Ubuntu | artful | * |
| Redis | Ubuntu | esm-infra-legacy/trusty | * |
| Redis | Ubuntu | precise | * |
| Redis | Ubuntu | trusty | * |
| Redis | Ubuntu | trusty/esm | * |
| Redis | Ubuntu | upstream | * |
| Redis | Ubuntu | utopic | * |
| Redis | Ubuntu | vivid | * |
| Redis | Ubuntu | wily | * |
| Redis | Ubuntu | yakkety | * |
| Redis | Ubuntu | zesty | * |