8.8
CVSSv3

CVE-2022-31144

Published: 19/07/2022 Updated: 07/10/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch before 7.0.4. The patch is released in version 7.0.4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redis redis

Github Repositories

CVE-2022-31144 dos pt redis, not finished yet or too soon, this can be turned into rce but oh well if you smart enough

CVE-2022-31144 CVE-2022-31144 dos 4redis Rce not finished yet or too soon, this can be turned into rce but oh well if you smart enough