PT-2024-33084 · Redis · Redis

Published

2024-11-03

·

Updated

2024-11-04

·

CVE-2024-48342

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Redis versions 2.60 through 7.41
Description The issue allows for a denial of service due to memory consumption when authentication is enabled. This occurs because the client-output-buffer-limit normal setting has no limit.
Recommendations For Redis versions 2.60 through 7.41, consider setting a limit for the client-output-buffer-limit normal to prevent excessive memory consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-48342

Affected Products

Redis