Beveiligingsadvies

CVE-2024-25115

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-04-09 17:31:48
Laatst bijgewerkt 2024-08-01 23:36:21
Toegewezen door GitHub_M
CVSS-score 7.0
Status PUBLISHED

Beschrijving

RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.