'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2025-10-15 | |
| Rule Name: | Redis Lua Script Sandbox Escape Vulnerability (CVE-2025-49844) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Redis is an open-source, log-based, key-value storage database developed by Redis Inc. (USA). It is written in ANSI C, supports network connectivity, can operate as an in-memory database or persist data to disk, and provides APIs in multiple programming languages.Redis versions 8.2.1 and earlier contain a resource management error vulnerability. This vulnerability arises because a specially crafted Lua script can manipulate the garbage collector, triggering a use-after-free condition, which may result in remote code execution. | |
| Impact: | Successful Exploit will result into Remote Code Execution. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://github.com/redis/redis/commit/d5728cb5795c966c5b5b1e0f0ac576a7e69af539 https://github.com/redis/redis/releases/tag/8.2.2 https://github.com/redis/redis/security/advisories/GHSA-4789-qfc9-5f9q |
|
| Solutions |
|---|
| Update vendor's patch or upgrade to latest version |