Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Tom Levy

#47416de 55,126
5.5CVSS total
Vulnerabilidades · 1
PT-2023-1718
5.5
2023-02-28
Redis · Redis · CVE-2022-36021
**Name of the Vulnerable Software and Affected Versions** Redis versions prior to 6.0.18 Redis versions prior to 6.2.11 Redis versions prior to 7.0.9 **Description** Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. **Recommendations** Update to Redis version 6.0.18 or later for versions prior to 6.0.18. Update to Redis version 6.2.11 or later for versions prior to 6.2.11. Update to Redis version 7.0.9 or later for versions prior to 7.0.9. As a temporary workaround, consider restricting the use of `SCAN` and `KEYS` commands with specially crafted patterns until a patch is available.