• CVE-2024-51741

发布时间: 2025年1月7日

修改时间: 2025年4月2日

概要

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2.

CVSS v3 指标

NVD openEuler
Confidentiality None None
Attack Vector Local Local
CVSS评分 N/A 4.4
Attack Complexity Low Low
Privileges Required High High
Scope Unchanged Unchanged
Integrity None None
User Interaction None None
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1009 Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, triggers a server panic and subsequent denial of service. The problem is fixed in Redis 7.2.7 and 7.4.2. 2025年1月15日

影响产品

产品 状态
KY3.4-5 redis Unaffected
KY3.5.2 redis Unaffected
KY3.5.3 redis Unaffected
V6 redis Unaffected