10
CVSSv2

CVE-2015-4335

Published: 09/06/2015 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Redis prior to 2.8.21 and 3.x prior to 3.0.2 allows remote malicious users to execute arbitrary Lua bytecode via the eval command.

Vulnerable Product Search on Vulmon Subscribe to Product

redislabs redis 3.0.0

redislabs redis 3.0.1

redislabs redis

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

It was discovered that redis, a persistent key-value database, could execute insecure Lua bytecode by way of the EVAL command This could allow remote attackers to break out of the Lua sandbox and execute arbitrary code For the stable distribution (jessie), this problem has been fixed in version 2:2817-1+deb8u1 For the testing distribution (str ...