CVE-2015-4335: Critical severity redis vulnerability
Published Jun 9, 2015
·Updated
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
Affected Software
5 affected components
Redislabs Redis<=2.8.20
Redislabs Redis=3.0.0
Redislabs Redis=3.0.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jun 9, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4335?
CVE-2015-4335 is considered a critical vulnerability due to its ability to allow remote execution of arbitrary Lua bytecode.
2
How do I fix CVE-2015-4335?
To fix CVE-2015-4335, upgrade Redis to version 2.8.21 or 3.0.2 or later.
3
Which versions are affected by CVE-2015-4335?
CVE-2015-4335 affects Redis versions prior to 2.8.21 and 3.x prior to 3.0.2.
4
What can attackers do with CVE-2015-4335?
Attackers can use CVE-2015-4335 to execute arbitrary code on vulnerable Redis servers using the eval command.
5
Is CVE-2015-4335 specific to any operating system?
CVE-2015-4335 can affect any system running the vulnerable versions of Redis, including Debian Linux.