In Redis versions prior to 6.2.16, 7.2.6 and 7.4.1 a high severity vulnerability CVE-2024-31449 was detected. An authenticated user can exploit a vulnerability in Redis by using a crafted Lua script, potentially leading to remote code execution. Users are advised to upgrade to the latest version to mitigate this risk. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-31449.
Redis: Critical Vulnerability Allows Remote Code Execution via Lua Script
by the Hossted team
09.10.2024